93.7 MB
/srv/reproducible-results/rbuild-debian/r-b-build.VsiIv6mL/b1/scap-security-guide_0.1.76-1_arm64.changes vs.
/srv/reproducible-results/rbuild-debian/r-b-build.VsiIv6mL/b2/scap-security-guide_0.1.76-1_arm64.changes
824 B
Files
    
Offset 1, 6 lines modifiedOffset 1, 6 lines modified
  
1 ·c5876af82a37cd0d6aeb3ad281ef0092·153832·admin·optional·ssg-applications_0.1.76-1_all.deb1 ·4177346ee1b6451d7c1613cf5f44a6b6·153740·admin·optional·ssg-applications_0.1.76-1_all.deb
2 ·ea0c1f19113a8a6c0a6e8b10e8e208a9·32632·admin·optional·ssg-base_0.1.76-1_all.deb2 ·ea0c1f19113a8a6c0a6e8b10e8e208a9·32632·admin·optional·ssg-base_0.1.76-1_all.deb
3 ·bf7bac2809ae4741dfbfcfc0db40ab0a·3725628·admin·optional·ssg-debderived_0.1.76-1_all.deb 
4 ·fcd3eb20c308d0a21bf0e3e00278c909·1232392·admin·optional·ssg-debian_0.1.76-1_all.deb 
5 ·515571b41fade010227c2f94e4609929·37100756·admin·optional·ssg-nondebian_0.1.76-1_all.deb3 ·c88e8e42baee3fc6124affc29224cd85·3725852·admin·optional·ssg-debderived_0.1.76-1_all.deb
 4 ·20f9dfa3980fc7b181f978e2989303ac·1232184·admin·optional·ssg-debian_0.1.76-1_all.deb
 5 ·f73dffb0b8e85ebe6b507af289d02441·37100544·admin·optional·ssg-nondebian_0.1.76-1_all.deb
402 KB
ssg-applications_0.1.76-1_all.deb
367 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0·····1728·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1728·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0···151912·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0···151820·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
401 KB
data.tar.xz
401 KB
data.tar
78.9 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
78.8 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:google:chromium-browser">28 ······<cpe-dict:cpe-item·name="cpe:/a:google:chromium-browser">
29 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Chromium.·It·is·a·rendering·of40 configuration·settings·for·Chromium.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 1675, 15 lines modifiedOffset 1675, 15 lines modified
1675 ··········<xccdf-1.2:check·system="http://scap.nist.gov/schema/ocil/2">1675 ··········<xccdf-1.2:check·system="http://scap.nist.gov/schema/ocil/2">
1676 ············<xccdf-1.2:check-content-ref·href="ssg-chromium-ocil.xml"·name="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"/>1676 ············<xccdf-1.2:check-content-ref·href="ssg-chromium-ocil.xml"·name="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"/>
1677 ··········</xccdf-1.2:check>1677 ··········</xccdf-1.2:check>
1678 ········</xccdf-1.2:Rule>1678 ········</xccdf-1.2:Rule>
1679 ······</xccdf-1.2:Group>1679 ······</xccdf-1.2:Group>
1680 ····</xccdf-1.2:Benchmark>1680 ····</xccdf-1.2:Benchmark>
1681 ··</ds:component>1681 ··</ds:component>
1682 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-oval.xml"·timestamp="2025-02-28T20:08:00">1682 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-oval.xml"·timestamp="2025-03-01T22:08:00">
1683 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">1683 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
1684 ······<oval-def:generator>1684 ······<oval-def:generator>
1685 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>1685 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
1686 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>1686 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
1687 ········<oval:schema_version>5.11</oval:schema_version>1687 ········<oval:schema_version>5.11</oval:schema_version>
1688 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>1688 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
1689 ······</oval-def:generator>1689 ······</oval-def:generator>
Offset 2539, 813 lines modifiedOffset 2539, 813 lines modified
2539 ········<oval-def:external_variable·id="oval:ssg-var_enable_encrypted_searching:var:1"·version="1"·datatype="string"·comment="Expected·search·provider·name"/>2539 ········<oval-def:external_variable·id="oval:ssg-var_enable_encrypted_searching:var:1"·version="1"·datatype="string"·comment="Expected·search·provider·name"/>
2540 ········<oval-def:external_variable·id="oval:ssg-var_extension_whitelist:var:1"·version="1"·datatype="string"·comment="Expected·approved·extensions"/>2540 ········<oval-def:external_variable·id="oval:ssg-var_extension_whitelist:var:1"·version="1"·datatype="string"·comment="Expected·approved·extensions"/>
2541 ········<oval-def:external_variable·id="oval:ssg-var_auth_schema:var:1"·version="1"·datatype="string"·comment="Expected·HTTP·authentication·type"/>2541 ········<oval-def:external_variable·id="oval:ssg-var_auth_schema:var:1"·version="1"·datatype="string"·comment="Expected·HTTP·authentication·type"/>
2542 ········<oval-def:external_variable·id="oval:ssg-var_trusted_home_page:var:1"·version="1"·datatype="string"·comment="Expected·home·page"/>2542 ········<oval-def:external_variable·id="oval:ssg-var_trusted_home_page:var:1"·version="1"·datatype="string"·comment="Expected·home·page"/>
2543 ······</oval-def:variables>2543 ······</oval-def:variables>
2544 ····</oval-def:oval_definitions>2544 ····</oval-def:oval_definitions>
2545 ··</ds:component>2545 ··</ds:component>
2546 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-ocil.xml"·timestamp="2025-02-28T20:08:00">2546 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-ocil.xml"·timestamp="2025-03-01T22:08:00">
2547 ····<ocil:ocil>2547 ····<ocil:ocil>
2548 ······<ocil:generator>2548 ······<ocil:generator>
2549 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>2549 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
2550 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>2550 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
2551 ········<ocil:schema_version>2.0</ocil:schema_version>2551 ········<ocil:schema_version>2.0</ocil:schema_version>
2552 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>2552 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
2553 ······</ocil:generator>2553 ······</ocil:generator>
2554 ······<ocil:questionnaires>2554 ······<ocil:questionnaires>
2555 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1"> 
2556 ··········<ocil:title>Enable·Only·Approved·Plugins</ocil:title> 
2557 ··········<ocil:actions> 
2558 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref> 
2559 ··········</ocil:actions> 
2560 ········</ocil:questionnaire> 
2561 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_autocomplete_ocil:questionnaire:1">2555 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_popups_ocil:questionnaire:1">
2562 ··········<ocil:title>Disable·the·AutoFill·Feature</ocil:title>2556 ··········<ocil:title>Disable·Popups</ocil:title>
2563 ··········<ocil:actions>2557 ··········<ocil:actions>
2564 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_autocomplete_action:testaction:1</ocil:test_action_ref>2558 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_popups_action:testaction:1</ocil:test_action_ref>
2565 ··········</ocil:actions>2559 ··········</ocil:actions>
2566 ········</ocil:questionnaire>2560 ········</ocil:questionnaire>
2567 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_password_manager_ocil:questionnaire:1">2561 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_incognito_mode_ocil:questionnaire:1">
2568 ··········<ocil:title>Disable·Chromium·Password·Manager</ocil:title>2562 ··········<ocil:title>Disable·Incognito·Mode</ocil:title>
2569 ··········<ocil:actions>2563 ··········<ocil:actions>
2570 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_password_manager_action:testaction:1</ocil:test_action_ref>2564 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_incognito_mode_action:testaction:1</ocil:test_action_ref>
2571 ··········</ocil:actions>2565 ··········</ocil:actions>
2572 ········</ocil:questionnaire>2566 ········</ocil:questionnaire>
2573 ········<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">2567 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">
2574 ··········<ocil:title>Disable·Location·Tracking</ocil:title>2568 ··········<ocil:title>Disable·Metrics·Reporting</ocil:title>
2575 ··········<ocil:actions>2569 ··········<ocil:actions>
2576 ············<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>2570 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>
2577 ··········</ocil:actions>2571 ··········</ocil:actions>
2578 ········</ocil:questionnaire>2572 ········</ocil:questionnaire>
2579 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_thirdparty_cookies_ocil:questionnaire:1">2573 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_encrypted_searching_ocil:questionnaire:1">
2580 ··········<ocil:title>Disable·3rd·Party·Cookies</ocil:title>2574 ··········<ocil:title>Enable·Encrypted·Searching</ocil:title>
2581 ··········<ocil:actions>2575 ··········<ocil:actions>
2582 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_thirdparty_cookies_action:testaction:1</ocil:test_action_ref>2576 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_encrypted_searching_action:testaction:1</ocil:test_action_ref>
2583 ··········</ocil:actions>2577 ··········</ocil:actions>
2584 ········</ocil:questionnaire>2578 ········</ocil:questionnaire>
2585 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1">2579 ········<ocil:questionnaire·id="ocil:ssg-chromium_blacklist_extension_installation_ocil:questionnaire:1">
2586 ··········<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title>2580 ··········<ocil:title>Disable·All·Extensions·by·Default</ocil:title>
2587 ··········<ocil:actions>2581 ··········<ocil:actions>
2588 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref>2582 ············<ocil:test_action_ref>ocil:ssg-chromium_blacklist_extension_installation_action:testaction:1</ocil:test_action_ref>
2589 ··········</ocil:actions>2583 ··········</ocil:actions>
2590 ········</ocil:questionnaire>2584 ········</ocil:questionnaire>
2591 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">2585 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">
2592 ··········<ocil:title>Enable·Saving·the·Browser·History</ocil:title>2586 ··········<ocil:title>Enable·Saving·the·Browser·History</ocil:title>
2593 ··········<ocil:actions>2587 ··········<ocil:actions>
2594 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>2588 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>
2595 ··········</ocil:actions>2589 ··········</ocil:actions>
2596 ········</ocil:questionnaire>2590 ········</ocil:questionnaire>
2597 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_search_suggestions_ocil:questionnaire:1">2591 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1">
2598 ··········<ocil:title>Disable·Search·Suggestion</ocil:title>2592 ··········<ocil:title>Enable·Only·Approved·Plugins</ocil:title>
2599 ··········<ocil:actions>2593 ··········<ocil:actions>
2600 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_search_suggestions_action:testaction:1</ocil:test_action_ref>2594 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref>
2601 ··········</ocil:actions>2595 ··········</ocil:actions>
2602 ········</ocil:questionnaire>2596 ········</ocil:questionnaire>
2603 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">2597 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_google_sync_ocil:questionnaire:1">
2604 ··········<ocil:title>Enable·the·Default·Search·Provider</ocil:title>2598 ··········<ocil:title>Disable·Data·Synchronization·to·Google</ocil:title>
2605 ··········<ocil:actions>2599 ··········<ocil:actions>
2606 ············<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref>2600 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_google_sync_action:testaction:1</ocil:test_action_ref>
2607 ··········</ocil:actions>2601 ··········</ocil:actions>
2608 ········</ocil:questionnaire>2602 ········</ocil:questionnaire>
2609 ········<ocil:questionnaire·id="ocil:ssg-chromium_check_cert_revocation_ocil:questionnaire:1">2603 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1">
2610 ··········<ocil:title>Enable·Online·OCSP/CRL·Certificate·Checks</ocil:title>2604 ··········<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title>
2611 ··········<ocil:actions>2605 ··········<ocil:actions>
2612 ············<ocil:test_action_ref>ocil:ssg-chromium_check_cert_revocation_action:testaction:1</ocil:test_action_ref>2606 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref>
2613 ··········</ocil:actions>2607 ··········</ocil:actions>
2614 ········</ocil:questionnaire>2608 ········</ocil:questionnaire>
2615 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_3d_graphics_api_ocil:questionnaire:1">2609 ········<ocil:questionnaire·id="ocil:ssg-chromium_extension_whitelist_ocil:questionnaire:1">
2616 ··········<ocil:title>Disable·the·3D·Graphics·APIs</ocil:title>2610 ··········<ocil:title>Enable·Only·Approved·Extensions</ocil:title>
2617 ··········<ocil:actions>2611 ··········<ocil:actions>
2618 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_3d_graphics_api_action:testaction:1</ocil:test_action_ref>2612 ············<ocil:test_action_ref>ocil:ssg-chromium_extension_whitelist_action:testaction:1</ocil:test_action_ref>
2619 ··········</ocil:actions>2613 ··········</ocil:actions>
2620 ········</ocil:questionnaire>2614 ········</ocil:questionnaire>
2621 ········<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1">2615 ········<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1">
2622 ··········<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title>2616 ··········<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title>
2623 ··········<ocil:actions>2617 ··········<ocil:actions>
2624 ············<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref>2618 ············<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref>
2625 ··········</ocil:actions>2619 ··········</ocil:actions>
Max diff block lines reached; 68785/80560 bytes (85.38%) of diff not shown.
70.3 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ocil.xml
70.2 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ocil.xml
Ordering differences only
    
Offset 3, 795 lines modifiedOffset 3, 795 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1"> 
11 ······<ocil:title>Enable·Only·Approved·Plugins</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_autocomplete_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_popups_ocil:questionnaire:1">
17 ······<ocil:title>Disable·the·AutoFill·Feature</ocil:title>11 ······<ocil:title>Disable·Popups</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_autocomplete_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_popups_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_password_manager_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_incognito_mode_ocil:questionnaire:1">
23 ······<ocil:title>Disable·Chromium·Password·Manager</ocil:title>17 ······<ocil:title>Disable·Incognito·Mode</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_password_manager_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_incognito_mode_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">
29 ······<ocil:title>Disable·Location·Tracking</ocil:title>23 ······<ocil:title>Disable·Metrics·Reporting</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_thirdparty_cookies_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_encrypted_searching_ocil:questionnaire:1">
35 ······<ocil:title>Disable·3rd·Party·Cookies</ocil:title>29 ······<ocil:title>Enable·Encrypted·Searching</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_thirdparty_cookies_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_encrypted_searching_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-chromium_blacklist_extension_installation_ocil:questionnaire:1">
41 ······<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title>35 ······<ocil:title>Disable·All·Extensions·by·Default</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-chromium_blacklist_extension_installation_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">
47 ······<ocil:title>Enable·Saving·the·Browser·History</ocil:title>41 ······<ocil:title>Enable·Saving·the·Browser·History</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_search_suggestions_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1">
53 ······<ocil:title>Disable·Search·Suggestion</ocil:title>47 ······<ocil:title>Enable·Only·Approved·Plugins</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_search_suggestions_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_google_sync_ocil:questionnaire:1">
59 ······<ocil:title>Enable·the·Default·Search·Provider</ocil:title>53 ······<ocil:title>Disable·Data·Synchronization·to·Google</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_google_sync_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-chromium_check_cert_revocation_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1">
65 ······<ocil:title>Enable·Online·OCSP/CRL·Certificate·Checks</ocil:title>59 ······<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-chromium_check_cert_revocation_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_3d_graphics_api_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-chromium_extension_whitelist_ocil:questionnaire:1">
71 ······<ocil:title>Disable·the·3D·Graphics·APIs</ocil:title>65 ······<ocil:title>Enable·Only·Approved·Extensions</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_3d_graphics_api_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-chromium_extension_whitelist_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1">
77 ······<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title>71 ······<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1">
83 ······<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title>77 ······<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cloud_print_sharing_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_thirdparty_cookies_ocil:questionnaire:1">
89 ······<ocil:title>Disable·Cloud·Print·Sharing</ocil:title>83 ······<ocil:title>Disable·3rd·Party·Cookies</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cloud_print_sharing_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_thirdparty_cookies_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cleartext_passwords_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-chromium_check_cert_revocation_ocil:questionnaire:1">
95 ······<ocil:title>Disable·Use·of·Cleartext·Passwords</ocil:title>89 ······<ocil:title>Enable·Online·OCSP/CRL·Certificate·Checks</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cleartext_passwords_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-chromium_check_cert_revocation_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_firewall_traversal_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-chromium_policy_file_ocil:questionnaire:1">
101 ······<ocil:title>Disable·Chromium's·Ability·to·Traverse·Firewalls</ocil:title>95 ······<ocil:title>Ensure·the·Chromium·Policy·Configuration·File·Exists</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_firewall_traversal_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-chromium_policy_file_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cleartext_passwords_ocil:questionnaire:1">
107 ······<ocil:title>Disable·Metrics·Reporting</ocil:title>101 ······<ocil:title>Disable·Use·of·Cleartext·Passwords</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cleartext_passwords_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_safe_browsing_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_network_prediction_ocil:questionnaire:1">
113 ······<ocil:title>Enable·the·Safe·Browsing·Feature</ocil:title>107 ······<ocil:title>Disable·Network·Prediction</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_safe_browsing_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_network_prediction_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_encrypted_searching_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_session_cookies_ocil:questionnaire:1">
119 ······<ocil:title>Enable·Encrypted·Searching</ocil:title>113 ······<ocil:title>Disable·Session·Cookies</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_encrypted_searching_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_session_cookies_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_incognito_mode_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-chromium_http_authentication_ocil:questionnaire:1">
125 ······<ocil:title>Disable·Incognito·Mode</ocil:title>119 ······<ocil:title>Set·Chromium's·HTTP·Authentication·Scheme</ocil:title>
126 ······<ocil:actions>120 ······<ocil:actions>
127 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_incognito_mode_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-chromium_http_authentication_action:testaction:1</ocil:test_action_ref>
128 ······</ocil:actions>122 ······</ocil:actions>
129 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
Max diff block lines reached; 59378/71723 bytes (82.79%) of diff not shown.
78.0 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
77.9 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service:1">28 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service:1">
29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service_node:1.21">32 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service_node:1.21">
33 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·1.21</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·1.21</cpe-dict:title>
Offset 35, 15 lines modifiedOffset 35, 15 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:elastic_kubernetes_service_node:1">36 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:elastic_kubernetes_service_node:1">
37 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2025-02-28T20:08:00">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2025-03-01T22:08:00">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of48 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 1545, 15 lines modifiedOffset 1545, 15 lines modified
1545 ··············<xccdf-1.2:check-content-ref·href="ssg-eks-ocil.xml"·name="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"/>1545 ··············<xccdf-1.2:check-content-ref·href="ssg-eks-ocil.xml"·name="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"/>
1546 ············</xccdf-1.2:check>1546 ············</xccdf-1.2:check>
1547 ··········</xccdf-1.2:Rule>1547 ··········</xccdf-1.2:Rule>
1548 ········</xccdf-1.2:Group>1548 ········</xccdf-1.2:Group>
1549 ······</xccdf-1.2:Group>1549 ······</xccdf-1.2:Group>
1550 ····</xccdf-1.2:Benchmark>1550 ····</xccdf-1.2:Benchmark>
1551 ··</ds:component>1551 ··</ds:component>
1552 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-oval.xml"·timestamp="2025-02-28T20:08:00">1552 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-oval.xml"·timestamp="2025-03-01T22:08:00">
1553 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">1553 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
1554 ······<oval-def:generator>1554 ······<oval-def:generator>
1555 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>1555 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
1556 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>1556 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
1557 ········<oval:schema_version>5.11</oval:schema_version>1557 ········<oval:schema_version>5.11</oval:schema_version>
1558 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>1558 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
1559 ······</oval-def:generator>1559 ······</oval-def:generator>
Offset 2166, 330 lines modifiedOffset 2166, 330 lines modified
2166 ········<oval-def:external_variable·id="oval:ssg-var_streaming_connection_timeouts:var:1"·version="1"·datatype="string"·comment="variable"/>2166 ········<oval-def:external_variable·id="oval:ssg-var_streaming_connection_timeouts:var:1"·version="1"·datatype="string"·comment="variable"/>
2167 ········<oval-def:local_variable·id="oval:ssg-kubelet_read_only_port_secured_file_location:var:1"·version="1"·datatype="string"·comment="The·actual·path·of·the·file·to·scan.">2167 ········<oval-def:local_variable·id="oval:ssg-kubelet_read_only_port_secured_file_location:var:1"·version="1"·datatype="string"·comment="The·actual·path·of·the·file·to·scan.">
2168 ··········<oval-def:literal_component>/etc/kubernetes/compliance-operator/kubeletconfig/openscap-kubeletconfig</oval-def:literal_component>2168 ··········<oval-def:literal_component>/etc/kubernetes/compliance-operator/kubeletconfig/openscap-kubeletconfig</oval-def:literal_component>
2169 ········</oval-def:local_variable>2169 ········</oval-def:local_variable>
2170 ······</oval-def:variables>2170 ······</oval-def:variables>
2171 ····</oval-def:oval_definitions>2171 ····</oval-def:oval_definitions>
2172 ··</ds:component>2172 ··</ds:component>
2173 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-ocil.xml"·timestamp="2025-02-28T20:08:00">2173 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-ocil.xml"·timestamp="2025-03-01T22:08:00">
2174 ····<ocil:ocil>2174 ····<ocil:ocil>
2175 ······<ocil:generator>2175 ······<ocil:generator>
2176 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>2176 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
2177 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>2177 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
2178 ········<ocil:schema_version>2.0</ocil:schema_version>2178 ········<ocil:schema_version>2.0</ocil:schema_version>
2179 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>2179 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
2180 ······</ocil:generator>2180 ······</ocil:generator>
2181 ······<ocil:questionnaires>2181 ······<ocil:questionnaires>
2182 ········<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1"> 
2183 ··········<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title> 
2184 ··········<ocil:actions> 
2185 ············<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref> 
2186 ··········</ocil:actions> 
2187 ········</ocil:questionnaire> 
2188 ········<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1">2182 ········<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1">
2189 ··········<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title>2183 ··········<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title>
2190 ··········<ocil:actions>2184 ··········<ocil:actions>
2191 ············<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref>2185 ············<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref>
2192 ··········</ocil:actions>2186 ··········</ocil:actions>
2193 ········</ocil:questionnaire>2187 ········</ocil:questionnaire>
2194 ········<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1">2188 ········<ocil:questionnaire·id="ocil:ssg-approved_registries_ocil:questionnaire:1">
2195 ··········<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>2189 ··········<ocil:title>Only·use·approved·container·registries</ocil:title>
2196 ··········<ocil:actions>2190 ··········<ocil:actions>
2197 ············<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>2191 ············<ocil:test_action_ref>ocil:ssg-approved_registries_action:testaction:1</ocil:test_action_ref>
2198 ··········</ocil:actions>2192 ··········</ocil:actions>
2199 ········</ocil:questionnaire>2193 ········</ocil:questionnaire>
2200 ········<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_conf_ocil:questionnaire:1">2194 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1">
2201 ··········<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title>2195 ··········<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title>
2202 ··········<ocil:actions>2196 ··········<ocil:actions>
 2197 ············<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
 2198 ··········</ocil:actions>
 2199 ········</ocil:questionnaire>
 2200 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_server_cert_rotation_ocil:questionnaire:1">
 2201 ··········<ocil:title>kubelet·-·Enable·Server·Certificate·Rotation</ocil:title>
 2202 ··········<ocil:actions>
 2203 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_server_cert_rotation_action:testaction:1</ocil:test_action_ref>
 2204 ··········</ocil:actions>
 2205 ········</ocil:questionnaire>
 2206 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1">
 2207 ··········<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
 2208 ··········<ocil:actions>
2203 ············<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref>2209 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref>
2204 ··········</ocil:actions>2210 ··········</ocil:actions>
2205 ········</ocil:questionnaire>2211 ········</ocil:questionnaire>
2206 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_ocil:questionnaire:1">2212 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_ocil:questionnaire:1">
2207 ··········<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>2213 ··········<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>
2208 ··········<ocil:actions>2214 ··········<ocil:actions>
2209 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_action:testaction:1</ocil:test_action_ref>2215 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_action:testaction:1</ocil:test_action_ref>
2210 ··········</ocil:actions>2216 ··········</ocil:actions>
2211 ········</ocil:questionnaire>2217 ········</ocil:questionnaire>
2212 ········<ocil:questionnaire·id="ocil:ssg-control_plane_access_ocil:questionnaire:1">2218 ········<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1">
2213 ··········<ocil:title>Restrict·Access·to·the·Control·Plane·Endpoint</ocil:title>2219 ··········<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>
2214 ··········<ocil:actions>2220 ··········<ocil:actions>
2215 ············<ocil:test_action_ref>ocil:ssg-control_plane_access_action:testaction:1</ocil:test_action_ref>2221 ············<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref>
2216 ··········</ocil:actions>2222 ··········</ocil:actions>
2217 ········</ocil:questionnaire>2223 ········</ocil:questionnaire>
2218 ········<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">2224 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_kubelet_conf_ocil:questionnaire:1">
2219 ··········<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>2225 ··········<ocil:title>Verify·Permissions·on·The·Kubelet·Configuration·File</ocil:title>
2220 ··········<ocil:actions>2226 ··········<ocil:actions>
2221 ············<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>2227 ············<ocil:test_action_ref>ocil:ssg-file_permissions_kubelet_conf_action:testaction:1</ocil:test_action_ref>
2222 ··········</ocil:actions>2228 ··········</ocil:actions>
2223 ········</ocil:questionnaire>2229 ········</ocil:questionnaire>
2224 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1">2230 ········<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">
2225 ··········<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title>2231 ··········<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title>
2226 ··········<ocil:actions>2232 ··········<ocil:actions>
2227 ············<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>2233 ············<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref>
2228 ··········</ocil:actions>2234 ··········</ocil:actions>
2229 ········</ocil:questionnaire>2235 ········</ocil:questionnaire>
2230 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_defaults_ocil:questionnaire:1">2236 ········<ocil:questionnaire·id="ocil:ssg-fargate_ocil:questionnaire:1">
2231 ··········<ocil:title>kubelet·-·Enable·Protect·Kernel·Defaults</ocil:title>2237 ··········<ocil:title>Consider·Fargate·for·Untrusted·Workloads</ocil:title>
2232 ··········<ocil:actions>2238 ··········<ocil:actions>
Max diff block lines reached; 67983/79679 bytes (85.32%) of diff not shown.
69.5 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ocil.xml
69.4 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ocil.xml
Ordering differences only
    
Offset 3, 321 lines modifiedOffset 3, 321 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1"> 
11 ······<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1">
17 ······<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title>11 ······<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1"> 
23 ······<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-approved_registries_ocil:questionnaire:1">
 17 ······<ocil:title>Only·use·approved·container·registries</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-approved_registries_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_conf_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1">
29 ······<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title>23 ······<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
 25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
 26 ······</ocil:actions>
 27 ····</ocil:questionnaire>
 28 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_server_cert_rotation_ocil:questionnaire:1">
 29 ······<ocil:title>kubelet·-·Enable·Server·Certificate·Rotation</ocil:title>
 30 ······<ocil:actions>
 31 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_server_cert_rotation_action:testaction:1</ocil:test_action_ref>
 32 ······</ocil:actions>
 33 ····</ocil:questionnaire>
 34 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1">
 35 ······<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
 36 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>38 ······</ocil:actions>
33 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_ocil:questionnaire:1">
35 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>41 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>
36 ······<ocil:actions>42 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>44 ······</ocil:actions>
39 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-control_plane_access_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1">
41 ······<ocil:title>Restrict·Access·to·the·Control·Plane·Endpoint</ocil:title>47 ······<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>
42 ······<ocil:actions>48 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-control_plane_access_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>50 ······</ocil:actions>
45 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_kubelet_conf_ocil:questionnaire:1">
47 ······<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>53 ······<ocil:title>Verify·Permissions·on·The·Kubelet·Configuration·File</ocil:title>
48 ······<ocil:actions>54 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_kubelet_conf_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>56 ······</ocil:actions>
51 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">
53 ······<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title>59 ······<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title>
54 ······<ocil:actions>60 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>62 ······</ocil:actions>
57 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_defaults_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-fargate_ocil:questionnaire:1">
59 ······<ocil:title>kubelet·-·Enable·Protect·Kernel·Defaults</ocil:title>65 ······<ocil:title>Consider·Fargate·for·Untrusted·Workloads</ocil:title>
60 ······<ocil:actions>66 ······<ocil:actions>
 67 ········<ocil:test_action_ref>ocil:ssg-fargate_action:testaction:1</ocil:test_action_ref>
 68 ······</ocil:actions>
 69 ····</ocil:questionnaire>
 70 ····<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_ocil:questionnaire:1">
 71 ······<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>
 72 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_protect_kernel_defaults_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_action:testaction:1</ocil:test_action_ref>
 74 ······</ocil:actions>
 75 ····</ocil:questionnaire>
 76 ····<ocil:questionnaire·id="ocil:ssg-control_plane_access_ocil:questionnaire:1">
 77 ······<ocil:title>Restrict·Access·to·the·Control·Plane·Endpoint</ocil:title>
 78 ······<ocil:actions>
 79 ········<ocil:test_action_ref>ocil:ssg-control_plane_access_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>80 ······</ocil:actions>
63 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1">
65 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>83 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>
66 ······<ocil:actions>84 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>86 ······</ocil:actions>
69 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
 88 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1">
 89 ······<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>
 90 ······<ocil:actions>
 91 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref>
 92 ······</ocil:actions>
 93 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_logging_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-audit_logging_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·Audit·Logging·is·Enabled</ocil:title>95 ······<ocil:title>Ensure·Audit·Logging·is·Enabled</ocil:title>
72 ······<ocil:actions>96 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_logging_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_logging_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>98 ······</ocil:actions>
75 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1">
77 ······<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title>101 ······<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>
78 ······<ocil:actions>102 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>104 ······</ocil:actions>
81 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kubelet_authorization_mode_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_conf_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·authorization·is·set·to·Webhook</ocil:title>107 ······<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
84 ······<ocil:actions>108 ······<ocil:actions>
 109 ········<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref>
 110 ······</ocil:actions>
 111 ····</ocil:questionnaire>
 112 ····<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1">
 113 ······<ocil:title>Ensure·Private·Endpoint·Access</ocil:title>
 114 ······<ocil:actions>
 115 ········<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref>
 116 ······</ocil:actions>
 117 ····</ocil:questionnaire>
 118 ····<ocil:questionnaire·id="ocil:ssg-private_nodes_ocil:questionnaire:1">
 119 ······<ocil:title>Ensure·Cluster·Private·Nodes</ocil:title>
 120 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kubelet_authorization_mode_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-private_nodes_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 61525/70903 bytes (86.77%) of diff not shown.
55.8 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
55.7 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:mozilla:firefox">28 ······<cpe-dict:cpe-item·name="cpe:/a:mozilla:firefox">
29 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Firefox.·It·is·a·rendering·of40 configuration·settings·for·Firefox.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 3488, 15 lines modifiedOffset 3488, 15 lines modified
3488 ··············<xccdf-1.2:check-content-ref·href="ssg-firefox-ocil.xml"·name="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"/>3488 ··············<xccdf-1.2:check-content-ref·href="ssg-firefox-ocil.xml"·name="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"/>
3489 ············</xccdf-1.2:check>3489 ············</xccdf-1.2:check>
3490 ··········</xccdf-1.2:Rule>3490 ··········</xccdf-1.2:Rule>
3491 ········</xccdf-1.2:Group>3491 ········</xccdf-1.2:Group>
3492 ······</xccdf-1.2:Group>3492 ······</xccdf-1.2:Group>
3493 ····</xccdf-1.2:Benchmark>3493 ····</xccdf-1.2:Benchmark>
3494 ··</ds:component>3494 ··</ds:component>
3495 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-oval.xml"·timestamp="2025-02-28T20:08:00">3495 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-oval.xml"·timestamp="2025-03-01T22:08:00">
3496 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">3496 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
3497 ······<oval-def:generator>3497 ······<oval-def:generator>
3498 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>3498 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
3499 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>3499 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
3500 ········<oval:schema_version>5.11</oval:schema_version>3500 ········<oval:schema_version>5.11</oval:schema_version>
3501 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>3501 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
3502 ······</oval-def:generator>3502 ······</oval-def:generator>
Offset 5198, 304 lines modifiedOffset 5198, 304 lines modified
5198 ··············<oval-def:literal_component>/distribution</oval-def:literal_component>5198 ··············<oval-def:literal_component>/distribution</oval-def:literal_component>
5199 ············</oval-def:concat>5199 ············</oval-def:concat>
5200 ··········</oval-def:unique>5200 ··········</oval-def:unique>
5201 ········</oval-def:local_variable>5201 ········</oval-def:local_variable>
5202 ······</oval-def:variables>5202 ······</oval-def:variables>
5203 ····</oval-def:oval_definitions>5203 ····</oval-def:oval_definitions>
5204 ··</ds:component>5204 ··</ds:component>
5205 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-ocil.xml"·timestamp="2025-02-28T20:08:00">5205 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-ocil.xml"·timestamp="2025-03-01T22:08:00">
5206 ····<ocil:ocil>5206 ····<ocil:ocil>
5207 ······<ocil:generator>5207 ······<ocil:generator>
5208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>5208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>5209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
5210 ········<ocil:schema_version>2.0</ocil:schema_version>5210 ········<ocil:schema_version>2.0</ocil:schema_version>
5211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>5211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
5212 ······</ocil:generator>5212 ······</ocil:generator>
5213 ······<ocil:questionnaires>5213 ······<ocil:questionnaires>
5214 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">5214 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">
 5215 ··········<ocil:title>Disable·Firefox·Pocket</ocil:title>
5215 ··········<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title> 
5216 ··········<ocil:actions> 
5217 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref> 
5218 ··········</ocil:actions> 
5219 ········</ocil:questionnaire> 
5220 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"> 
5221 ··········<ocil:title>Enable·Shared·System·Certificates</ocil:title> 
5222 ··········<ocil:actions>5216 ··········<ocil:actions>
5223 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>5217 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>
5224 ··········</ocil:actions>5218 ··········</ocil:actions>
5225 ········</ocil:questionnaire>5219 ········</ocil:questionnaire>
5226 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">5220 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">
5227 ··········<ocil:title>Enable·Certificate·Verification</ocil:title>5221 ··········<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>
5228 ··········<ocil:actions>5222 ··········<ocil:actions>
5229 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>5223 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>
5230 ··········</ocil:actions>5224 ··········</ocil:actions>
5231 ········</ocil:questionnaire>5225 ········</ocil:questionnaire>
5232 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">5226 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">
5233 ··········<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>5227 ··········<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>
5234 ··········<ocil:actions>5228 ··········<ocil:actions>
5235 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>5229 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>
5236 ··········</ocil:actions>5230 ··········</ocil:actions>
5237 ········</ocil:questionnaire>5231 ········</ocil:questionnaire>
5238 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">5232 ········<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">
5239 ··········<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>5233 ··········<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>
5240 ··········<ocil:actions>5234 ··········<ocil:actions>
5241 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>5235 ············<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>
5242 ··········</ocil:actions>5236 ··········</ocil:actions>
5243 ········</ocil:questionnaire>5237 ········</ocil:questionnaire>
5244 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">5238 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1">
5245 ··········<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>5239 ··········<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title>
5246 ··········<ocil:actions>5240 ··········<ocil:actions>
5247 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>5241 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref>
5248 ··········</ocil:actions>5242 ··········</ocil:actions>
5249 ········</ocil:questionnaire>5243 ········</ocil:questionnaire>
5250 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">5244 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">
5251 ··········<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title>5245 ··········<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title>
5252 ··········<ocil:actions>5246 ··········<ocil:actions>
5253 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref>5247 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref>
5254 ··········</ocil:actions>5248 ··········</ocil:actions>
5255 ········</ocil:questionnaire>5249 ········</ocil:questionnaire>
5256 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_update_ocil:questionnaire:1">5250 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">
 5251 ··········<ocil:title>Enable·Certificate·Verification</ocil:title>
5257 ··········<ocil:title>Disable·Installed·Search·Plugins·Update·Checking</ocil:title> 
5258 ··········<ocil:actions> 
5259 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-search_update_action:testaction:1</ocil:test_action_ref> 
5260 ··········</ocil:actions> 
5261 ········</ocil:questionnaire> 
5262 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1"> 
5263 ··········<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title> 
5264 ··········<ocil:actions>5252 ··········<ocil:actions>
5265 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>5253 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>
5266 ··········</ocil:actions>5254 ··········</ocil:actions>
5267 ········</ocil:questionnaire>5255 ········</ocil:questionnaire>
5268 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1">5256 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">
5269 ··········<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title>5257 ··········<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>
5270 ··········<ocil:actions>5258 ··········<ocil:actions>
5271 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref>5259 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>
5272 ··········</ocil:actions>5260 ··········</ocil:actions>
5273 ········</ocil:questionnaire>5261 ········</ocil:questionnaire>
5274 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">5262 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">
5275 ··········<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>5263 ··········<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>
5276 ··········<ocil:actions>5264 ··········<ocil:actions>
5277 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>5265 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>
5278 ··········</ocil:actions>5266 ··········</ocil:actions>
5279 ········</ocil:questionnaire>5267 ········</ocil:questionnaire>
5280 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">5268 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">
5281 ··········<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>5269 ··········<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>
5282 ··········<ocil:actions>5270 ··········<ocil:actions>
Max diff block lines reached; 45320/56901 bytes (79.65%) of diff not shown.
48.7 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ocil.xml
48.6 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ocil.xml
Ordering differences only
    
Offset 3, 295 lines modifiedOffset 3, 295 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">
 11 ······<ocil:title>Disable·Firefox·Pocket</ocil:title>
11 ······<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"> 
17 ······<ocil:title>Enable·Shared·System·Certificates</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">
23 ······<ocil:title>Enable·Certificate·Verification</ocil:title>17 ······<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">
29 ······<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>23 ······<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1"> 
35 ······<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">
 29 ······<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1">
41 ······<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>35 ······<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">
47 ······<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title>41 ······<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_update_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">
 47 ······<ocil:title>Enable·Certificate·Verification</ocil:title>
53 ······<ocil:title>Disable·Installed·Search·Plugins·Update·Checking</ocil:title> 
54 ······<ocil:actions> 
55 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_update_action:testaction:1</ocil:test_action_ref> 
56 ······</ocil:actions> 
57 ····</ocil:questionnaire> 
58 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1"> 
59 ······<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title> 
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">
65 ······<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title>53 ······<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">
71 ······<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>59 ······<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">
77 ······<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>65 ······<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-dod_root_certificate_installed_ocil:questionnaire:1">
83 ······<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>71 ······<ocil:title>The·DoD·Root·Certificate·Exists</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-dod_root_certificate_installed_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">
89 ······<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>77 ······<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">
95 ······<ocil:title>Disable·Firefox·Development·Tools</ocil:title>83 ······<ocil:title>Disable·Firefox·Development·Tools</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1">
101 ······<ocil:title>Enabled·Firefox·Enhanced·Tracking·Protection</ocil:title>89 ······<ocil:title>Ensure·the·Content·Blocker·uBlock·Origin·is·Installed</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-content_blocker_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1">
107 ······<ocil:title>Disable·Firefox·deprecated·ciphers</ocil:title>95 ······<ocil:title>Enable·Shared·System·Certificates</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
 97 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>
 98 ······</ocil:actions>
 99 ····</ocil:questionnaire>
 100 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">
 101 ······<ocil:title>Disable·Firefox·network·prediction</ocil:title>
 102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_deprecated_ciphers_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>
 104 ······</ocil:actions>
 105 ····</ocil:questionnaire>
 106 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">
 107 ······<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>
 108 ······<ocil:actions>
 109 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">
113 ······<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>113 ······<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
Max diff block lines reached; 38371/49637 bytes (77.30%) of diff not shown.
9.93 MB
ssg-debderived_0.1.76-1_all.deb
367 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0·····3044·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0·····3044·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0··3722392·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0··3722616·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
9.93 MB
data.tar.xz
9.93 MB
data.tar
696 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
696 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.xenial.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.xenial.usn.oval.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.xenial.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.xenial.usn.oval.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~">30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~">
31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·16.04·(Xenial)</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·16.04·(Xenial)</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1604:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1604:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of42 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 63230, 15 lines modifiedOffset 63230, 15 lines modified
63230 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1604-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>63230 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1604-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
63231 ············</xccdf-1.2:check>63231 ············</xccdf-1.2:check>
63232 ··········</xccdf-1.2:Rule>63232 ··········</xccdf-1.2:Rule>
63233 ········</xccdf-1.2:Group>63233 ········</xccdf-1.2:Group>
63234 ······</xccdf-1.2:Group>63234 ······</xccdf-1.2:Group>
63235 ····</xccdf-1.2:Benchmark>63235 ····</xccdf-1.2:Benchmark>
63236 ··</ds:component>63236 ··</ds:component>
63237 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"·timestamp="2025-02-28T20:08:00">63237 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"·timestamp="2025-03-01T22:08:00">
63238 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">63238 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
63239 ······<oval-def:generator>63239 ······<oval-def:generator>
63240 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>63240 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
63241 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>63241 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
63242 ········<oval:schema_version>5.11</oval:schema_version>63242 ········<oval:schema_version>5.11</oval:schema_version>
63243 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>63243 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
63244 ······</oval-def:generator>63244 ······</oval-def:generator>
Offset 79818, 4346 lines modifiedOffset 79818, 4346 lines modified
79818 ············</oval-def:arithmetic>79818 ············</oval-def:arithmetic>
79819 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>79819 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
79820 ··········</oval-def:arithmetic>79820 ··········</oval-def:arithmetic>
79821 ········</oval-def:local_variable>79821 ········</oval-def:local_variable>
79822 ······</oval-def:variables>79822 ······</oval-def:variables>
79823 ····</oval-def:oval_definitions>79823 ····</oval-def:oval_definitions>
79824 ··</ds:component>79824 ··</ds:component>
79825 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"·timestamp="2025-02-28T20:08:00">79825 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"·timestamp="2025-03-01T22:08:00">
79826 ····<ocil:ocil>79826 ····<ocil:ocil>
79827 ······<ocil:generator>79827 ······<ocil:generator>
79828 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>79828 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
79829 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>79829 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
79830 ········<ocil:schema_version>2.0</ocil:schema_version>79830 ········<ocil:schema_version>2.0</ocil:schema_version>
79831 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>79831 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
79832 ······</ocil:generator>79832 ······</ocil:generator>
79833 ······<ocil:questionnaires>79833 ······<ocil:questionnaires>
79834 ········<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1"> 
79835 ··········<ocil:title>Set·Password·Minimum·Age</ocil:title> 
79836 ··········<ocil:actions> 
79837 ············<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref> 
79838 ··········</ocil:actions> 
79839 ········</ocil:questionnaire> 
79840 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1"> 
79841 ··········<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title> 
79842 ··········<ocil:actions> 
79843 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref> 
79844 ··········</ocil:actions> 
79845 ········</ocil:questionnaire> 
79846 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> 
79847 ··········<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title> 
79848 ··········<ocil:actions> 
79849 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref> 
79850 ··········</ocil:actions> 
79851 ········</ocil:questionnaire> 
79852 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1">79834 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">
79853 ··········<ocil:title>Disable·the·IPv6·protocol</ocil:title>79835 ··········<ocil:title>Enable·module·signature·verification</ocil:title>
79854 ··········<ocil:actions>79836 ··········<ocil:actions>
79855 ············<ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref>79837 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>
79856 ··········</ocil:actions>79838 ··········</ocil:actions>
79857 ········</ocil:questionnaire>79839 ········</ocil:questionnaire>
79858 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">79840 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">
79859 ··········<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>79841 ··········<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>
79860 ··········<ocil:actions>79842 ··········<ocil:actions>
79861 ············<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>79843 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>
79862 ··········</ocil:actions>79844 ··········</ocil:actions>
79863 ········</ocil:questionnaire>79845 ········</ocil:questionnaire>
79864 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">79846 ········<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1">
79865 ··········<ocil:title>Enable·module·signature·verification</ocil:title>79847 ··········<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title>
79866 ··········<ocil:actions>79848 ··········<ocil:actions>
79867 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>79849 ············<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref>
79868 ··········</ocil:actions>79850 ··········</ocil:actions>
79869 ········</ocil:questionnaire>79851 ········</ocil:questionnaire>
79870 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1">79852 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1">
79871 ··········<ocil:title>Disable·Kerberos·Authentication</ocil:title>79853 ··········<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title>
79872 ··········<ocil:actions>79854 ··········<ocil:actions>
79873 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref>79855 ············<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref>
79874 ··········</ocil:actions>79856 ··········</ocil:actions>
79875 ········</ocil:questionnaire>79857 ········</ocil:questionnaire>
79876 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1">79858 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1">
79877 ··········<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title>79859 ··········<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title>
79878 ··········<ocil:actions>79860 ··········<ocil:actions>
79879 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref>79861 ············<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>
79880 ··········</ocil:actions>79862 ··········</ocil:actions>
79881 ········</ocil:questionnaire>79863 ········</ocil:questionnaire>
79882 ········<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1">79864 ········<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1">
79883 ··········<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title>79865 ··········<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title>
79884 ··········<ocil:actions>79866 ··········<ocil:actions>
79885 ············<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref>79867 ············<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref>
79886 ··········</ocil:actions>79868 ··········</ocil:actions>
79887 ········</ocil:questionnaire>79869 ········</ocil:questionnaire>
79888 ········<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1">79870 ········<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">
 79871 ··········<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>
79889 ··········<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title> 
79890 ··········<ocil:actions> 
79891 ············<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref> 
79892 ··········</ocil:actions> 
79893 ········</ocil:questionnaire> 
79894 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1"> 
79895 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title> 
79896 ··········<ocil:actions>79872 ··········<ocil:actions>
79897 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>79873 ············<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>
79898 ··········</ocil:actions>79874 ··········</ocil:actions>
79899 ········</ocil:questionnaire>79875 ········</ocil:questionnaire>
79900 ········<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_ocil:questionnaire:1">79876 ········<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1">
79901 ··········<ocil:title>Prevent·Login·to·Accounts·With·Empty·Password</ocil:title>79877 ··········<ocil:title>Do·Not·Allow·SSH·Environment·Options</ocil:title>
79902 ··········<ocil:actions>79878 ··········<ocil:actions>
79903 ············<ocil:test_action_ref>ocil:ssg-no_empty_passwords_action:testaction:1</ocil:test_action_ref>79879 ············<ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 701676/712562 bytes (98.47%) of diff not shown.
662 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ocil.xml
662 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ocil.xml
Ordering differences only
    
Offset 3, 4337 lines modifiedOffset 3, 4337 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1"> 
11 ······<ocil:title>Set·Password·Minimum·Age</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1"> 
17 ······<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> 
23 ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">
29 ······<ocil:title>Disable·the·IPv6·protocol</ocil:title>11 ······<ocil:title>Enable·module·signature·verification</ocil:title>
30 ······<ocil:actions>12 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>14 ······</ocil:actions>
33 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">
35 ······<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>17 ······<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>
36 ······<ocil:actions>18 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>20 ······</ocil:actions>
39 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1">
41 ······<ocil:title>Enable·module·signature·verification</ocil:title>23 ······<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1">
47 ······<ocil:title>Disable·Kerberos·Authentication</ocil:title>29 ······<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1"> 
53 ······<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1">
 35 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title>
54 ······<ocil:actions>36 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>38 ······</ocil:actions>
57 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1">
59 ······<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title>41 ······<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title>
60 ······<ocil:actions>42 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>44 ······</ocil:actions>
63 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">
 47 ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>
65 ······<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title> 
66 ······<ocil:actions> 
67 ········<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref> 
68 ······</ocil:actions> 
69 ····</ocil:questionnaire> 
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1"> 
71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title> 
72 ······<ocil:actions>48 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>50 ······</ocil:actions>
75 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1">
77 ······<ocil:title>Prevent·Login·to·Accounts·With·Empty·Password</ocil:title>53 ······<ocil:title>Do·Not·Allow·SSH·Environment·Options</ocil:title>
78 ······<ocil:actions>54 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-no_empty_passwords_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>56 ······</ocil:actions>
81 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-service_chronyd_enabled_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1">
83 ······<ocil:title>The·Chronyd·service·is·enabled</ocil:title>59 ······<ocil:title>Ensure·LDAP·client·is·not·installed</ocil:title>
84 ······<ocil:actions>60 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-service_chronyd_enabled_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-package_openldap-clients_removed_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>62 ······</ocil:actions>
87 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-securetty_root_login_console_only_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-service_timesyncd_enabled_ocil:questionnaire:1">
89 ······<ocil:title>Restrict·Virtual·Console·Root·Logins</ocil:title>65 ······<ocil:title>Enable·systemd_timesyncd·Service</ocil:title>
90 ······<ocil:actions>66 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-securetty_root_login_console_only_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-service_timesyncd_enabled_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>68 ······</ocil:actions>
93 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1">
95 ······<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title>71 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>
96 ······<ocil:actions>72 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>74 ······</ocil:actions>
99 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1">
101 ······<ocil:title>Verify·User·Who·Owns·Backup·gshadow·File</ocil:title>77 ······<ocil:title>Enable·automatic·signing·of·all·modules</ocil:title>
102 ······<ocil:actions>78 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_all_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>80 ······</ocil:actions>
105 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·LDAP·client·is·not·installed</ocil:title>83 ······<ocil:title>Enable·different·security·models</ocil:title>
108 ······<ocil:actions>84 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-package_openldap-clients_removed_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>86 ······</ocil:actions>
111 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1">
113 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>89 ······<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title>
114 ······<ocil:actions>90 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>92 ······</ocil:actions>
117 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lchown_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">
119 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lchown</ocil:title>95 ······<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>
120 ······<ocil:actions>96 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lchown_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>98 ······</ocil:actions>
123 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_list_ocil:questionnaire:1">
125 ······<ocil:title>Verify·Permissions·on·/var/log·Directory</ocil:title>101 ······<ocil:title>Enable·checks·on·linked·list·manipulation</ocil:title>
126 ······<ocil:actions>102 ······<ocil:actions>
127 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_list_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 666295/677683 bytes (98.32%) of diff not shown.
725 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
725 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.bionic.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.bionic.usn.oval.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.bionic.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.bionic.usn.oval.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~">30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~">
31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·18.04·(Bionic·Beaver)</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·18.04·(Bionic·Beaver)</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1804:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1804:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of42 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 67111, 15 lines modifiedOffset 67111, 15 lines modified
67111 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1804-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>67111 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1804-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
67112 ············</xccdf-1.2:check>67112 ············</xccdf-1.2:check>
67113 ··········</xccdf-1.2:Rule>67113 ··········</xccdf-1.2:Rule>
67114 ········</xccdf-1.2:Group>67114 ········</xccdf-1.2:Group>
67115 ······</xccdf-1.2:Group>67115 ······</xccdf-1.2:Group>
67116 ····</xccdf-1.2:Benchmark>67116 ····</xccdf-1.2:Benchmark>
67117 ··</ds:component>67117 ··</ds:component>
67118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"·timestamp="2025-02-28T20:08:00">67118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"·timestamp="2025-03-01T22:08:00">
67119 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">67119 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
67120 ······<oval-def:generator>67120 ······<oval-def:generator>
67121 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>67121 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
67122 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>67122 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
67123 ········<oval:schema_version>5.11</oval:schema_version>67123 ········<oval:schema_version>5.11</oval:schema_version>
67124 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>67124 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
67125 ······</oval-def:generator>67125 ······</oval-def:generator>
Offset 84657, 2958 lines modifiedOffset 84657, 2958 lines modified
84657 ············</oval-def:arithmetic>84657 ············</oval-def:arithmetic>
84658 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>84658 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
84659 ··········</oval-def:arithmetic>84659 ··········</oval-def:arithmetic>
84660 ········</oval-def:local_variable>84660 ········</oval-def:local_variable>
84661 ······</oval-def:variables>84661 ······</oval-def:variables>
84662 ····</oval-def:oval_definitions>84662 ····</oval-def:oval_definitions>
84663 ··</ds:component>84663 ··</ds:component>
84664 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"·timestamp="2025-02-28T20:08:00">84664 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"·timestamp="2025-03-01T22:08:00">
84665 ····<ocil:ocil>84665 ····<ocil:ocil>
84666 ······<ocil:generator>84666 ······<ocil:generator>
84667 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>84667 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
84668 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>84668 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
84669 ········<ocil:schema_version>2.0</ocil:schema_version>84669 ········<ocil:schema_version>2.0</ocil:schema_version>
84670 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>84670 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
84671 ······</ocil:generator>84671 ······</ocil:generator>
84672 ······<ocil:questionnaires>84672 ······<ocil:questionnaires>
84673 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_info_ocil:questionnaire:1">84673 ········<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
84674 ··········<ocil:title>Set·LogLevel·to·INFO</ocil:title>84674 ··········<ocil:title>Enable·systemd-journald·Service</ocil:title>
84675 ··········<ocil:actions>84675 ··········<ocil:actions>
84676 ············<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_info_action:testaction:1</ocil:test_action_ref>84676 ············<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
84677 ··········</ocil:actions>84677 ··········</ocil:actions>
84678 ········</ocil:questionnaire>84678 ········</ocil:questionnaire>
84679 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1"> 
84680 ··········<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title>84679 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1">
 84680 ··········<ocil:title>Enable·Yama·support</ocil:title>
84681 ··········<ocil:actions>84681 ··········<ocil:actions>
84682 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref>84682 ············<ocil:test_action_ref>ocil:ssg-kernel_config_security_yama_action:testaction:1</ocil:test_action_ref>
84683 ··········</ocil:actions>84683 ··········</ocil:actions>
84684 ········</ocil:questionnaire>84684 ········</ocil:questionnaire>
84685 ········<ocil:questionnaire·id="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1">84685 ········<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nodev_ocil:questionnaire:1">
84686 ··········<ocil:title>Ensure·SMEP·is·not·disabled·during·boot</ocil:title>84686 ··········<ocil:title>Add·nodev·Option·to·/tmp</ocil:title>
84687 ··········<ocil:actions>84687 ··········<ocil:actions>
84688 ············<ocil:test_action_ref>ocil:ssg-grub2_nosmep_argument_absent_action:testaction:1</ocil:test_action_ref>84688 ············<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nodev_action:testaction:1</ocil:test_action_ref>
84689 ··········</ocil:actions>84689 ··········</ocil:actions>
84690 ········</ocil:questionnaire>84690 ········</ocil:questionnaire>
84691 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">84691 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">
84692 ··········<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>84692 ··········<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>
84693 ··········<ocil:actions>84693 ··········<ocil:actions>
84694 ············<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>84694 ············<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>
84695 ··········</ocil:actions>84695 ··········</ocil:actions>
84696 ········</ocil:questionnaire>84696 ········</ocil:questionnaire>
84697 ········<ocil:questionnaire·id="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1">84697 ········<ocil:questionnaire·id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1">
84698 ··········<ocil:title>Enforce·Spectre·v2·mitigation</ocil:title>84698 ··········<ocil:title>Prefer·to·use·a·64-bit·Operating·System·when·supported</ocil:title>
84699 ··········<ocil:actions>84699 ··········<ocil:actions>
84700 ············<ocil:test_action_ref>ocil:ssg-grub2_spectre_v2_argument_action:testaction:1</ocil:test_action_ref>84700 ············<ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref>
84701 ··········</ocil:actions>84701 ··········</ocil:actions>
84702 ········</ocil:questionnaire>84702 ········</ocil:questionnaire>
84703 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1"> 
84704 ··········<ocil:title>Ensure·No·World-Writable·Files·Exist</ocil:title>84703 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_ocil:questionnaire:1">
 84704 ··········<ocil:title>Record·Events·that·Modify·User/Group·Information</ocil:title>
84705 ··········<ocil:actions>84705 ··········<ocil:actions>
84706 ············<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_world_writable_action:testaction:1</ocil:test_action_ref>84706 ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_action:testaction:1</ocil:test_action_ref>
84707 ··········</ocil:actions>84707 ··········</ocil:actions>
84708 ········</ocil:questionnaire>84708 ········</ocil:questionnaire>
84709 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">84709 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">
84710 ··········<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>84710 ··········<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>
84711 ··········<ocil:actions>84711 ··········<ocil:actions>
84712 ············<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>84712 ············<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>
84713 ··········</ocil:actions>84713 ··········</ocil:actions>
84714 ········</ocil:questionnaire>84714 ········</ocil:questionnaire>
84715 ········<ocil:questionnaire·id="ocil:ssg-coredump_disable_backtraces_ocil:questionnaire:1">84715 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1">
84716 ··········<ocil:title>Disable·core·dump·backtraces</ocil:title>84716 ··········<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title>
84717 ··········<ocil:actions>84717 ··········<ocil:actions>
84718 ············<ocil:test_action_ref>ocil:ssg-coredump_disable_backtraces_action:testaction:1</ocil:test_action_ref>84718 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>
84719 ··········</ocil:actions>84719 ··········</ocil:actions>
84720 ········</ocil:questionnaire>84720 ········</ocil:questionnaire>
84721 ········<ocil:questionnaire·id="ocil:ssg-account_unique_name_ocil:questionnaire:1">84721 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">
84722 ··········<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·Names</ocil:title>84722 ··········<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>
84723 ··········<ocil:actions>84723 ··········<ocil:actions>
84724 ············<ocil:test_action_ref>ocil:ssg-account_unique_name_action:testaction:1</ocil:test_action_ref>84724 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>
84725 ··········</ocil:actions>84725 ··········</ocil:actions>
84726 ········</ocil:questionnaire>84726 ········</ocil:questionnaire>
84727 ········<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_pub_key_ocil:questionnaire:1"> 
84728 ··········<ocil:title>Verify·Group·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>84727 ········<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1">
 84728 ··········<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title>
84729 ··········<ocil:actions>84729 ··········<ocil:actions>
84730 ············<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>84730 ············<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref>
84731 ··········</ocil:actions>84731 ··········</ocil:actions>
84732 ········</ocil:questionnaire>84732 ········</ocil:questionnaire>
84733 ········<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_relayhost_ocil:questionnaire:1">84733 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1">
84734 ··········<ocil:title>Configure·System·to·Forward·All·Mail·through·a·specific·host</ocil:title>84734 ··········<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>
84735 ··········<ocil:actions>84735 ··········<ocil:actions>
84736 ············<ocil:test_action_ref>ocil:ssg-postfix_client_configure_relayhost_action:testaction:1</ocil:test_action_ref>84736 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>
84737 ··········</ocil:actions>84737 ··········</ocil:actions>
84738 ········</ocil:questionnaire>84738 ········</ocil:questionnaire>
84739 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">84739 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1">
84740 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>84740 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>
Max diff block lines reached; 729696/742017 bytes (98.34%) of diff not shown.
690 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ocil.xml
689 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ocil.xml
Ordering differences only
    
Offset 3, 2949 lines modifiedOffset 3, 2949 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_info_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
11 ······<ocil:title>Set·LogLevel·to·INFO</ocil:title>11 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_info_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1"> 
17 ······<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1">
 17 ······<ocil:title>Enable·Yama·support</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_yama_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nodev_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·SMEP·is·not·disabled·during·boot</ocil:title>23 ······<ocil:title>Add·nodev·Option·to·/tmp</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmep_argument_absent_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nodev_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">
29 ······<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>29 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1">
35 ······<ocil:title>Enforce·Spectre·v2·mitigation</ocil:title>35 ······<ocil:title>Prefer·to·use·a·64-bit·Operating·System·when·supported</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-grub2_spectre_v2_argument_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1"> 
41 ······<ocil:title>Ensure·No·World-Writable·Files·Exist</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_ocil:questionnaire:1">
 41 ······<ocil:title>Record·Events·that·Modify·User/Group·Information</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_world_writable_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1"> 
47 ······<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">
 47 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-coredump_disable_backtraces_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1">
53 ······<ocil:title>Disable·core·dump·backtraces</ocil:title>53 ······<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-coredump_disable_backtraces_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-account_unique_name_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·Names</ocil:title>59 ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-account_unique_name_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_pub_key_ocil:questionnaire:1"> 
65 ······<ocil:title>Verify·Group·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1">
 65 ······<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_relayhost_ocil:questionnaire:1"> 
71 ······<ocil:title>Configure·System·to·Forward·All·Mail·through·a·specific·host</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1">
 71 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_relayhost_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1">
77 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>77 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-securetty_root_login_console_only_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_sha512_ocil:questionnaire:1">
83 ······<ocil:title>Restrict·Virtual·Console·Root·Logins</ocil:title>83 ······<ocil:title>Sign·kernel·modules·with·SHA-512</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-securetty_root_login_console_only_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_sha512_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-package_audit_installed_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_proc_kcore_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·the·audit·Subsystem·is·Installed</ocil:title>89 ······<ocil:title>Disable·support·for·/proc/kkcore</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_proc_kcore_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-aide_disable_silentreports_ocil:questionnaire:1">
95 ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>95 ······<ocil:title>Configure·AIDE·To·Notify·Personnel·if·Baseline·Configurations·Are·Altered</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-aide_disable_silentreports_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-display_login_attempts_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-auditd_log_format_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·PAM·Displays·Last·Logon/Access·Notification</ocil:title>101 ······<ocil:title>Resolve·information·before·writing·to·audit·logs</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-display_login_attempts_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-auditd_log_format_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-service_ip6tables_enabled_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">
107 ······<ocil:title>Verify·ip6tables·Enabled·if·Using·IPv6</ocil:title>107 ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-service_ip6tables_enabled_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_stig_ocil:questionnaire:1">
113 ······<ocil:title>Disable·the·Automounter</ocil:title>113 ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_stig_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_permissions_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·System·Log·Files·Have·Correct·Permissions</ocil:title>119 ······<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_permissions_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_gshadow_ocil:questionnaire:1">
Max diff block lines reached; 693264/705909 bytes (98.21%) of diff not shown.
1.36 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
1.36 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~">28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~">
29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·20.04·(Focal·Fossa)</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·20.04·(Focal·Fossa)</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2004:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2004:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of40 configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 143123, 15 lines modifiedOffset 143123, 15 lines modified
143123 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2004-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>143123 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2004-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>
143124 ············</xccdf-1.2:check>143124 ············</xccdf-1.2:check>
143125 ··········</xccdf-1.2:Rule>143125 ··········</xccdf-1.2:Rule>
143126 ········</xccdf-1.2:Group>143126 ········</xccdf-1.2:Group>
143127 ······</xccdf-1.2:Group>143127 ······</xccdf-1.2:Group>
143128 ····</xccdf-1.2:Benchmark>143128 ····</xccdf-1.2:Benchmark>
143129 ··</ds:component>143129 ··</ds:component>
143130 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"·timestamp="2025-02-28T20:08:00">143130 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"·timestamp="2025-03-01T22:08:00">
143131 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">143131 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
143132 ······<oval-def:generator>143132 ······<oval-def:generator>
143133 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>143133 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
143134 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>143134 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
143135 ········<oval:schema_version>5.11</oval:schema_version>143135 ········<oval:schema_version>5.11</oval:schema_version>
143136 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>143136 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
143137 ······</oval-def:generator>143137 ······</oval-def:generator>
Offset 174684, 8954 lines modifiedOffset 174684, 8907 lines modified
174684 ············</oval-def:arithmetic>174684 ············</oval-def:arithmetic>
174685 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>174685 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
174686 ··········</oval-def:arithmetic>174686 ··········</oval-def:arithmetic>
174687 ········</oval-def:local_variable>174687 ········</oval-def:local_variable>
174688 ······</oval-def:variables>174688 ······</oval-def:variables>
174689 ····</oval-def:oval_definitions>174689 ····</oval-def:oval_definitions>
174690 ··</ds:component>174690 ··</ds:component>
174691 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"·timestamp="2025-02-28T20:08:00">174691 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"·timestamp="2025-03-01T22:08:00">
174692 ····<ocil:ocil>174692 ····<ocil:ocil>
174693 ······<ocil:generator>174693 ······<ocil:generator>
174694 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>174694 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
174695 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>174695 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
174696 ········<ocil:schema_version>2.0</ocil:schema_version>174696 ········<ocil:schema_version>2.0</ocil:schema_version>
174697 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>174697 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
174698 ······</ocil:generator>174698 ······</ocil:generator>
174699 ······<ocil:questionnaires>174699 ······<ocil:questionnaires>
174700 ········<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1"> 
174701 ··········<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>174700 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1">
 174701 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title>
174702 ··········<ocil:actions>174702 ··········<ocil:actions>
174703 ············<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>174703 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>
174704 ··········</ocil:actions>174704 ··········</ocil:actions>
174705 ········</ocil:questionnaire>174705 ········</ocil:questionnaire>
174706 ········<ocil:questionnaire·id="ocil:ssg-no_rsh_trust_files_ocil:questionnaire:1">174706 ········<ocil:questionnaire·id="ocil:ssg-package_iptables-persistent_removed_ocil:questionnaire:1">
174707 ··········<ocil:title>Remove·Rsh·Trust·Files</ocil:title>174707 ··········<ocil:title>Remove·iptables-persistent·Package</ocil:title>
174708 ··········<ocil:actions>174708 ··········<ocil:actions>
174709 ············<ocil:test_action_ref>ocil:ssg-no_rsh_trust_files_action:testaction:1</ocil:test_action_ref>174709 ············<ocil:test_action_ref>ocil:ssg-package_iptables-persistent_removed_action:testaction:1</ocil:test_action_ref>
174710 ··········</ocil:actions>174710 ··········</ocil:actions>
174711 ········</ocil:questionnaire>174711 ········</ocil:questionnaire>
174712 ········<ocil:questionnaire·id="ocil:ssg-sudo_add_requiretty_ocil:questionnaire:1">174712 ········<ocil:questionnaire·id="ocil:ssg-coredump_disable_storage_ocil:questionnaire:1">
174713 ··········<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·requiretty</ocil:title>174713 ··········<ocil:title>Disable·storing·core·dump</ocil:title>
174714 ··········<ocil:actions>174714 ··········<ocil:actions>
174715 ············<ocil:test_action_ref>ocil:ssg-sudo_add_requiretty_action:testaction:1</ocil:test_action_ref>174715 ············<ocil:test_action_ref>ocil:ssg-coredump_disable_storage_action:testaction:1</ocil:test_action_ref>
174716 ··········</ocil:actions>174716 ··········</ocil:actions>
174717 ········</ocil:questionnaire>174717 ········</ocil:questionnaire>
174718 ········<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_kex_ocil:questionnaire:1">174718 ········<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1">
174719 ··········<ocil:title>Use·Only·Strong·Key·Exchange·algorithms</ocil:title>174719 ··········<ocil:title>Verify·iptables·Enabled</ocil:title>
174720 ··········<ocil:actions>174720 ··········<ocil:actions>
174721 ············<ocil:test_action_ref>ocil:ssg-sshd_use_strong_kex_action:testaction:1</ocil:test_action_ref>174721 ············<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref>
174722 ··········</ocil:actions>174722 ··········</ocil:actions>
174723 ········</ocil:questionnaire>174723 ········</ocil:questionnaire>
174724 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1"> 
174725 ··········<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>174724 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">
 174725 ··········<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>
174726 ··········<ocil:actions>174726 ··········<ocil:actions>
174727 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref>174727 ············<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>
174728 ··········</ocil:actions>174728 ··········</ocil:actions>
174729 ········</ocil:questionnaire>174729 ········</ocil:questionnaire>
174730 ········<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1"> 
174731 ··········<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>174730 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_banner_enabled_ocil:questionnaire:1">
 174731 ··········<ocil:title>Enable·GNOME3·Login·Warning·Banner</ocil:title>
174732 ··········<ocil:actions>174732 ··········<ocil:actions>
174733 ············<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>174733 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_banner_enabled_action:testaction:1</ocil:test_action_ref>
174734 ··········</ocil:actions>174734 ··········</ocil:actions>
174735 ········</ocil:questionnaire>174735 ········</ocil:questionnaire>
174736 ········<ocil:questionnaire·id="ocil:ssg-sudo_vdsm_nopasswd_ocil:questionnaire:1">174736 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1">
174737 ··········<ocil:title>Only·the·VDSM·User·Can·Use·sudo·NOPASSWD</ocil:title>174737 ··········<ocil:title>Ensure·all·users·last·password·change·date·is·in·the·past</ocil:title>
174738 ··········<ocil:actions>174738 ··········<ocil:actions>
174739 ············<ocil:test_action_ref>ocil:ssg-sudo_vdsm_nopasswd_action:testaction:1</ocil:test_action_ref>174739 ············<ocil:test_action_ref>ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1</ocil:test_action_ref>
174740 ··········</ocil:actions>174740 ··········</ocil:actions>
174741 ········</ocil:questionnaire>174741 ········</ocil:questionnaire>
174742 ········<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1">174742 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_ocil:questionnaire:1">
174743 ··········<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title>174743 ··········<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv6·Interfaces</ocil:title>
174744 ··········<ocil:actions>174744 ··········<ocil:actions>
174745 ············<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref>174745 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>
174746 ··········</ocil:actions>174746 ··········</ocil:actions>
174747 ········</ocil:questionnaire>174747 ········</ocil:questionnaire>
174748 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_dmesg_restrict_ocil:questionnaire:1">174748 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_ocil:questionnaire:1">
174749 ··········<ocil:title>Restrict·Access·to·Kernel·Message·Buffer</ocil:title>174749 ··········<ocil:title>Disable·Accepting·Packets·Routed·Between·Local·Interfaces</ocil:title>
174750 ··········<ocil:actions>174750 ··········<ocil:actions>
174751 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_dmesg_restrict_action:testaction:1</ocil:test_action_ref>174751 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_action:testaction:1</ocil:test_action_ref>
174752 ··········</ocil:actions>174752 ··········</ocil:actions>
174753 ········</ocil:questionnaire>174753 ········</ocil:questionnaire>
174754 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">174754 ········<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1">
174755 ··········<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>174755 ··········<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title>
174756 ··········<ocil:actions>174756 ··········<ocil:actions>
174757 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>174757 ············<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>
174758 ··········</ocil:actions>174758 ··········</ocil:actions>
174759 ········</ocil:questionnaire>174759 ········</ocil:questionnaire>
174760 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1">174760 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">
174761 ··········<ocil:title>Verify·Group·Ownership·of·Message·of·the·Day·Banner</ocil:title>174761 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>
174762 ··········<ocil:actions>174762 ··········<ocil:actions>
174763 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref>174763 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>
174764 ··········</ocil:actions>174764 ··········</ocil:actions>
174765 ········</ocil:questionnaire>174765 ········</ocil:questionnaire>
174766 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1"> 
174767 ··········<ocil:title>Ensure·Rsyslog·Authenticates·Off-Loaded·Audit·Records</ocil:title>174766 ········<ocil:questionnaire·id="ocil:ssg-no_direct_root_logins_ocil:questionnaire:1">
Max diff block lines reached; 1417606/1429833 bytes (99.14%) of diff not shown.
1.3 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ocil.xml
1.3 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ocil.xml
Ordering differences only
    
Offset 3, 8945 lines modifiedOffset 3, 8898 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1"> 
11 ······<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1">
 11 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-no_rsh_trust_files_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-package_iptables-persistent_removed_ocil:questionnaire:1">
17 ······<ocil:title>Remove·Rsh·Trust·Files</ocil:title>17 ······<ocil:title>Remove·iptables-persistent·Package</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-no_rsh_trust_files_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-package_iptables-persistent_removed_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_requiretty_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-coredump_disable_storage_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·requiretty</ocil:title>23 ······<ocil:title>Disable·storing·core·dump</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sudo_add_requiretty_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-coredump_disable_storage_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_kex_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1">
29 ······<ocil:title>Use·Only·Strong·Key·Exchange·algorithms</ocil:title>29 ······<ocil:title>Verify·iptables·Enabled</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sshd_use_strong_kex_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1"> 
35 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">
 35 ······<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1"> 
41 ······<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_banner_enabled_ocil:questionnaire:1">
 41 ······<ocil:title>Enable·GNOME3·Login·Warning·Banner</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_banner_enabled_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sudo_vdsm_nopasswd_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1">
47 ······<ocil:title>Only·the·VDSM·User·Can·Use·sudo·NOPASSWD</ocil:title>47 ······<ocil:title>Ensure·all·users·last·password·change·date·is·in·the·past</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sudo_vdsm_nopasswd_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1"> 
53 ······<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_ocil:questionnaire:1">
 53 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv6·Interfaces</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_dmesg_restrict_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_ocil:questionnaire:1">
59 ······<ocil:title>Restrict·Access·to·Kernel·Message·Buffer</ocil:title>59 ······<ocil:title>Disable·Accepting·Packets·Routed·Between·Local·Interfaces</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_dmesg_restrict_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1">
65 ······<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>65 ······<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Group·Ownership·of·Message·of·the·Day·Banner</ocil:title>71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1"> 
77 ······<ocil:title>Ensure·Rsyslog·Authenticates·Off-Loaded·Audit·Records</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-no_direct_root_logins_ocil:questionnaire:1">
 77 ······<ocil:title>Direct·root·Logins·Not·Allowed</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-no_direct_root_logins_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-partition_for_tmp_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·/tmp·Located·On·Separate·Partition</ocil:title>83 ······<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-partition_for_tmp_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmodat_ocil:questionnaire:1"> 
89 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmodat</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_shadow_ocil:questionnaire:1">
 89 ······<ocil:title>Verify·User·Who·Owns·Backup·shadow·File</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmodat_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-ntpd_configure_restrictions_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_nodev_ocil:questionnaire:1">
95 ······<ocil:title>Configure·server·restrictions·for·ntpd</ocil:title>95 ······<ocil:title>Add·nodev·Option·to·/var/tmp</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-ntpd_configure_restrictions_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_nodev_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_forward_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_session_events_wtmp_ocil:questionnaire:1">
101 ······<ocil:title>Set·Default·iptables·Policy·for·Forwarded·Packets</ocil:title>101 ······<ocil:title>Record·Attempts·to·Alter·Process·and·Session·Initiation·Information·wtmp</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_forward_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_session_events_wtmp_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-dir_perms_world_writable_sticky_bits_ocil:questionnaire:1"> 
107 ······<ocil:title>Verify·that·All·World-Writable·Directories·Have·Sticky·Bits·Set</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">
 107 ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_sticky_bits_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ssh_keysign_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·ssh-keysign</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-zipl_audit_backlog_limit_argument_ocil:questionnaire:1">
 113 ······<ocil:title>Extend·Audit·Backlog·Limit·for·the·Audit·Daemon·in·zIPL</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_ssh_keysign_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-zipl_audit_backlog_limit_argument_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1"> 
119 ······<ocil:title>Disable·Accepting·Router·Advertisements·on·all·IPv6·Interfaces·by·Default</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1">
 119 ······<ocil:title>Verify·Permissions·on·/etc/cron.allow·file</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
Max diff block lines reached; 1353920/1366580 bytes (99.07%) of diff not shown.
1.43 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
1.43 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~">28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~">
29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·22.04·(Jammy·Jellyfish)</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·22.04·(Jammy·Jellyfish)</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2204:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2204:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of40 configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 148842, 15 lines modifiedOffset 148842, 15 lines modified
148842 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2204-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>148842 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2204-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>
148843 ············</xccdf-1.2:check>148843 ············</xccdf-1.2:check>
148844 ··········</xccdf-1.2:Rule>148844 ··········</xccdf-1.2:Rule>
148845 ········</xccdf-1.2:Group>148845 ········</xccdf-1.2:Group>
148846 ······</xccdf-1.2:Group>148846 ······</xccdf-1.2:Group>
148847 ····</xccdf-1.2:Benchmark>148847 ····</xccdf-1.2:Benchmark>
148848 ··</ds:component>148848 ··</ds:component>
148849 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"·timestamp="2025-02-28T20:08:00">148849 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"·timestamp="2025-03-01T22:08:00">
148850 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">148850 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
148851 ······<oval-def:generator>148851 ······<oval-def:generator>
148852 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>148852 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
148853 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>148853 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
148854 ········<oval:schema_version>5.11</oval:schema_version>148854 ········<oval:schema_version>5.11</oval:schema_version>
148855 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>148855 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
148856 ······</oval-def:generator>148856 ······</oval-def:generator>
Offset 181748, 7513 lines modifiedOffset 181748, 7513 lines modified
181748 ············</oval-def:arithmetic>181748 ············</oval-def:arithmetic>
181749 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>181749 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
181750 ··········</oval-def:arithmetic>181750 ··········</oval-def:arithmetic>
181751 ········</oval-def:local_variable>181751 ········</oval-def:local_variable>
181752 ······</oval-def:variables>181752 ······</oval-def:variables>
181753 ····</oval-def:oval_definitions>181753 ····</oval-def:oval_definitions>
181754 ··</ds:component>181754 ··</ds:component>
181755 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"·timestamp="2025-02-28T20:08:00">181755 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"·timestamp="2025-03-01T22:08:00">
181756 ····<ocil:ocil>181756 ····<ocil:ocil>
181757 ······<ocil:generator>181757 ······<ocil:generator>
181758 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>181758 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
181759 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>181759 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
181760 ········<ocil:schema_version>2.0</ocil:schema_version>181760 ········<ocil:schema_version>2.0</ocil:schema_version>
181761 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>181761 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
181762 ······</ocil:generator>181762 ······</ocil:generator>
181763 ······<ocil:questionnaires>181763 ······<ocil:questionnaires>
181764 ········<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_private_key_ocil:questionnaire:1">181764 ········<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">
181765 ··········<ocil:title>Verify·Group·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>181765 ··········<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>
181766 ··········<ocil:actions>181766 ··········<ocil:actions>
181767 ············<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>181767 ············<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>
181768 ··········</ocil:actions>181768 ··········</ocil:actions>
181769 ········</ocil:questionnaire>181769 ········</ocil:questionnaire>
181770 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"> 
181771 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>181770 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1">
 181771 ··········<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title>
181772 ··········<ocil:actions>181772 ··········<ocil:actions>
181773 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>181773 ············<ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>
181774 ··········</ocil:actions>181774 ··········</ocil:actions>
181775 ········</ocil:questionnaire>181775 ········</ocil:questionnaire>
181776 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_credentials_ocil:questionnaire:1">181776 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1">
181777 ··········<ocil:title>Enable·checks·on·credential·management</ocil:title>181777 ··········<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>
181778 ··········<ocil:actions>181778 ··········<ocil:actions>
181779 ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_credentials_action:testaction:1</ocil:test_action_ref>181779 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>
181780 ··········</ocil:actions>181780 ··········</ocil:actions>
181781 ········</ocil:questionnaire>181781 ········</ocil:questionnaire>
181782 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1">181782 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1">
181783 ··········<ocil:title>Set·SSH·Client·Alive·Interval</ocil:title>181783 ··········<ocil:title>Disable·Accepting·Router·Advertisements·on·all·IPv6·Interfaces·by·Default</ocil:title>
181784 ··········<ocil:actions>181784 ··········<ocil:actions>
181785 ············<ocil:test_action_ref>ocil:ssg-sshd_set_idle_timeout_action:testaction:1</ocil:test_action_ref>181785 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1</ocil:test_action_ref>
181786 ··········</ocil:actions>181786 ··········</ocil:actions>
181787 ········</ocil:questionnaire>181787 ········</ocil:questionnaire>
181788 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_sudoers_d_ocil:questionnaire:1"> 
181789 ··········<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions·-·/etc/sudoers.d/</ocil:title>181788 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1">
 181789 ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>
181790 ··········<ocil:actions>181790 ··········<ocil:actions>
181791 ············<ocil:test_action_ref>ocil:ssg-audit_rules_sudoers_d_action:testaction:1</ocil:test_action_ref>181791 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>
181792 ··········</ocil:actions>181792 ··········</ocil:actions>
181793 ········</ocil:questionnaire>181793 ········</ocil:questionnaire>
181794 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_ocil:questionnaire:1">181794 ········<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">
181795 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv6·Interfaces</ocil:title>181795 ··········<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>
181796 ··········<ocil:actions>181796 ··········<ocil:actions>
181797 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>181797 ············<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>
181798 ··········</ocil:actions>181798 ··········</ocil:actions>
181799 ········</ocil:questionnaire>181799 ········</ocil:questionnaire>
181800 ········<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1">181800 ········<ocil:questionnaire·id="ocil:ssg-smartcard_configure_cert_checking_ocil:questionnaire:1">
181801 ··········<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title>181801 ··········<ocil:title>Configure·Smart·Card·Certificate·Status·Checking</ocil:title>
181802 ··········<ocil:actions>181802 ··········<ocil:actions>
181803 ············<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref>181803 ············<ocil:test_action_ref>ocil:ssg-smartcard_configure_cert_checking_action:testaction:1</ocil:test_action_ref>
181804 ··········</ocil:actions>181804 ··········</ocil:actions>
181805 ········</ocil:questionnaire>181805 ········</ocil:questionnaire>
181806 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">181806 ········<ocil:questionnaire·id="ocil:ssg-vlock_installed_ocil:questionnaire:1">
181807 ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>181807 ··········<ocil:title>Check·that·vlock·is·installed·to·allow·session·locking</ocil:title>
181808 ··········<ocil:actions>181808 ··········<ocil:actions>
181809 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>181809 ············<ocil:test_action_ref>ocil:ssg-vlock_installed_action:testaction:1</ocil:test_action_ref>
181810 ··········</ocil:actions>181810 ··········</ocil:actions>
181811 ········</ocil:questionnaire>181811 ········</ocil:questionnaire>
181812 ········<ocil:questionnaire·id="ocil:ssg-no_direct_root_logins_ocil:questionnaire:1">181812 ········<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_symlinks_ocil:questionnaire:1">
181813 ··········<ocil:title>Direct·root·Logins·Not·Allowed</ocil:title>181813 ··········<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Symlinks</ocil:title>
181814 ··········<ocil:actions>181814 ··········<ocil:actions>
181815 ············<ocil:test_action_ref>ocil:ssg-no_direct_root_logins_action:testaction:1</ocil:test_action_ref>181815 ············<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_symlinks_action:testaction:1</ocil:test_action_ref>
181816 ··········</ocil:actions>181816 ··········</ocil:actions>
181817 ········</ocil:questionnaire>181817 ········</ocil:questionnaire>
181818 ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_audit_nosuid_ocil:questionnaire:1">181818 ········<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1">
181819 ··········<ocil:title>Add·nosuid·Option·to·/var/log/audit</ocil:title>181819 ··········<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title>
181820 ··········<ocil:actions>181820 ··········<ocil:actions>
181821 ············<ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_nosuid_action:testaction:1</ocil:test_action_ref>181821 ············<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref>
181822 ··········</ocil:actions>181822 ··········</ocil:actions>
181823 ········</ocil:questionnaire>181823 ········</ocil:questionnaire>
181824 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_notifiers_ocil:questionnaire:1">181824 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1">
181825 ··········<ocil:title>Enable·checks·on·notifier·call·chains</ocil:title>181825 ··········<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title>
181826 ··········<ocil:actions>181826 ··········<ocil:actions>
181827 ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_notifiers_action:testaction:1</ocil:test_action_ref>181827 ············<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref>
181828 ··········</ocil:actions>181828 ··········</ocil:actions>
181829 ········</ocil:questionnaire>181829 ········</ocil:questionnaire>
181830 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1">181830 ········<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1">
181831 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>181831 ··········<ocil:title>Ensure·LDAP·client·is·not·installed</ocil:title>
181832 ··········<ocil:actions>181832 ··········<ocil:actions>
Max diff block lines reached; 1482255/1495028 bytes (99.15%) of diff not shown.
1.36 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ocil.xml
1.36 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ocil.xml
Ordering differences only
    
Offset 3, 7504 lines modifiedOffset 3, 7504 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_private_key_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">
11 ······<ocil:title>Verify·Group·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>11 ······<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"> 
17 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1">
 17 ······<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_credentials_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1">
23 ······<ocil:title>Enable·checks·on·credential·management</ocil:title>23 ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_credentials_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1">
29 ······<ocil:title>Set·SSH·Client·Alive·Interval</ocil:title>29 ······<ocil:title>Disable·Accepting·Router·Advertisements·on·all·IPv6·Interfaces·by·Default</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sshd_set_idle_timeout_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sudoers_d_ocil:questionnaire:1"> 
35 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions·-·/etc/sudoers.d/</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1">
 35 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sudoers_d_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_ocil:questionnaire:1"> 
41 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv6·Interfaces</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">
 41 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-smartcard_configure_cert_checking_ocil:questionnaire:1">
47 ······<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title>47 ······<ocil:title>Configure·Smart·Card·Certificate·Status·Checking</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-smartcard_configure_cert_checking_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-vlock_installed_ocil:questionnaire:1">
53 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>53 ······<ocil:title>Check·that·vlock·is·installed·to·allow·session·locking</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-vlock_installed_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-no_direct_root_logins_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_symlinks_ocil:questionnaire:1">
59 ······<ocil:title>Direct·root·Logins·Not·Allowed</ocil:title>59 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Symlinks</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-no_direct_root_logins_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_symlinks_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_audit_nosuid_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1">
65 ······<ocil:title>Add·nosuid·Option·to·/var/log/audit</ocil:title>65 ······<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_nosuid_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_notifiers_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1">
71 ······<ocil:title>Enable·checks·on·notifier·call·chains</ocil:title>71 ······<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_notifiers_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1"> 
77 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1">
 77 ······<ocil:title>Ensure·LDAP·client·is·not·installed</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-package_openldap-clients_removed_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_hibernation_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Permissions·on·crontab</ocil:title>83 ······<ocil:title>Disable·hibernation</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_hibernation_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_shadow_ocil:questionnaire:1"> 
89 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/shadow</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1">
 89 ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_shadow_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1"> 
95 ······<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1">
 95 ······<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1"> 
101 ······<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1">
 101 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-chronyd_run_as_chrony_user_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·that·chronyd·is·running·under·chrony·user·account</ocil:title>107 ······<ocil:title>Record·Any·Attempts·to·Run·chcon</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-chronyd_run_as_chrony_user_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_macs_ordered_stig_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_sudoedit_ocil:questionnaire:1">
113 ······<ocil:title>Use·Only·FIPS·140-2·Validated·MACs</ocil:title>113 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·sudoedit</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sshd_use_approved_macs_ordered_stig_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_sudoedit_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1">
119 ······<ocil:title>Limit·Users'·SSH·Access</ocil:title>119 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 1416441/1429334 bytes (99.10%) of diff not shown.
926 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ds.xml
926 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:24.04::~~lts~~~">28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:24.04::~~lts~~~">
29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·24.04·(Noble·Numbat)</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·24.04·(Noble·Numbat)</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2404:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2404:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_24-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_24-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·24.04</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·24.04</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Ubuntu·24.04.·It·is·a·rendering·of40 configuration·settings·for·Ubuntu·24.04.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 102298, 15 lines modifiedOffset 102298, 15 lines modified
102298 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2404-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>102298 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2404-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>
102299 ············</xccdf-1.2:check>102299 ············</xccdf-1.2:check>
102300 ··········</xccdf-1.2:Rule>102300 ··········</xccdf-1.2:Rule>
102301 ········</xccdf-1.2:Group>102301 ········</xccdf-1.2:Group>
102302 ······</xccdf-1.2:Group>102302 ······</xccdf-1.2:Group>
102303 ····</xccdf-1.2:Benchmark>102303 ····</xccdf-1.2:Benchmark>
102304 ··</ds:component>102304 ··</ds:component>
102305 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"·timestamp="2025-02-28T20:08:00">102305 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"·timestamp="2025-03-01T22:08:00">
102306 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">102306 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
102307 ······<oval-def:generator>102307 ······<oval-def:generator>
102308 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>102308 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
102309 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>102309 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
102310 ········<oval:schema_version>5.11</oval:schema_version>102310 ········<oval:schema_version>5.11</oval:schema_version>
102311 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>102311 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
102312 ······</oval-def:generator>102312 ······</oval-def:generator>
Offset 123597, 3952 lines modifiedOffset 123597, 3952 lines modified
123597 ············</oval-def:arithmetic>123597 ············</oval-def:arithmetic>
123598 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>123598 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
123599 ··········</oval-def:arithmetic>123599 ··········</oval-def:arithmetic>
123600 ········</oval-def:local_variable>123600 ········</oval-def:local_variable>
123601 ······</oval-def:variables>123601 ······</oval-def:variables>
123602 ····</oval-def:oval_definitions>123602 ····</oval-def:oval_definitions>
123603 ··</ds:component>123603 ··</ds:component>
123604 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"·timestamp="2025-02-28T20:08:00">123604 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"·timestamp="2025-03-01T22:08:00">
123605 ····<ocil:ocil>123605 ····<ocil:ocil>
123606 ······<ocil:generator>123606 ······<ocil:generator>
123607 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>123607 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
123608 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>123608 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
123609 ········<ocil:schema_version>2.0</ocil:schema_version>123609 ········<ocil:schema_version>2.0</ocil:schema_version>
123610 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>123610 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
123611 ······</ocil:generator>123611 ······</ocil:generator>
123612 ······<ocil:questionnaires>123612 ······<ocil:questionnaires>
123613 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_ocil:questionnaire:1">123613 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_info_ocil:questionnaire:1">
123614 ··········<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>123614 ··········<ocil:title>Set·LogLevel·to·INFO</ocil:title>
123615 ··········<ocil:actions>123615 ··········<ocil:actions>
123616 ············<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_action:testaction:1</ocil:test_action_ref>123616 ············<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_info_action:testaction:1</ocil:test_action_ref>
123617 ··········</ocil:actions>123617 ··········</ocil:actions>
123618 ········</ocil:questionnaire>123618 ········</ocil:questionnaire>
123619 ········<ocil:questionnaire·id="ocil:ssg-service_dovecot_disabled_ocil:questionnaire:1">123619 ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_audit_nosuid_ocil:questionnaire:1">
123620 ··········<ocil:title>Disable·Dovecot·Service</ocil:title>123620 ··········<ocil:title>Add·nosuid·Option·to·/var/log/audit</ocil:title>
123621 ··········<ocil:actions>123621 ··········<ocil:actions>
123622 ············<ocil:test_action_ref>ocil:ssg-service_dovecot_disabled_action:testaction:1</ocil:test_action_ref>123622 ············<ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_nosuid_action:testaction:1</ocil:test_action_ref>
123623 ··········</ocil:actions>123623 ··········</ocil:actions>
123624 ········</ocil:questionnaire>123624 ········</ocil:questionnaire>
123625 ········<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">123625 ········<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">
123626 ··········<ocil:title>Disable·XDMCP·in·GDM</ocil:title>123626 ··········<ocil:title>Verify·Owner·on·crontab</ocil:title>
123627 ··········<ocil:actions>123627 ··········<ocil:actions>
123628 ············<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>123628 ············<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref>
123629 ··········</ocil:actions>123629 ··········</ocil:actions>
123630 ········</ocil:questionnaire>123630 ········</ocil:questionnaire>
123631 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1">123631 ········<ocil:questionnaire·id="ocil:ssg-package_rsh_removed_ocil:questionnaire:1">
123632 ··········<ocil:title>Set·SSH·Client·Alive·Interval</ocil:title>123632 ··········<ocil:title>Uninstall·rsh·Package</ocil:title>
123633 ··········<ocil:actions>123633 ··········<ocil:actions>
123634 ············<ocil:test_action_ref>ocil:ssg-sshd_set_idle_timeout_action:testaction:1</ocil:test_action_ref>123634 ············<ocil:test_action_ref>ocil:ssg-package_rsh_removed_action:testaction:1</ocil:test_action_ref>
123635 ··········</ocil:actions>123635 ··········</ocil:actions>
123636 ········</ocil:questionnaire>123636 ········</ocil:questionnaire>
123637 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_yama_ptrace_scope_ocil:questionnaire:1">123637 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">
123638 ··········<ocil:title>Restrict·usage·of·ptrace·to·descendant·processes</ocil:title>123638 ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
123639 ··········<ocil:actions>123639 ··········<ocil:actions>
123640 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_yama_ptrace_scope_action:testaction:1</ocil:test_action_ref>123640 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>
123641 ··········</ocil:actions>123641 ··········</ocil:actions>
123642 ········</ocil:questionnaire>123642 ········</ocil:questionnaire>
123643 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1"> 
123644 ··········<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title>123643 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1">
 123644 ··········<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title>
123645 ··········<ocil:actions>123645 ··········<ocil:actions>
123646 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref>123646 ············<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref>
123647 ··········</ocil:actions>123647 ··········</ocil:actions>
123648 ········</ocil:questionnaire>123648 ········</ocil:questionnaire>
123649 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1">123649 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_usermod_ocil:questionnaire:1">
123650 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>123650 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·usermod</ocil:title>
123651 ··········<ocil:actions>123651 ··········<ocil:actions>
123652 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>123652 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_usermod_action:testaction:1</ocil:test_action_ref>
123653 ··········</ocil:actions>123653 ··········</ocil:actions>
123654 ········</ocil:questionnaire>123654 ········</ocil:questionnaire>
123655 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1">123655 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minlen_ocil:questionnaire:1">
123656 ··········<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>123656 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Length</ocil:title>
123657 ··········<ocil:actions>123657 ··········<ocil:actions>
123658 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>123658 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minlen_action:testaction:1</ocil:test_action_ref>
123659 ··········</ocil:actions>123659 ··········</ocil:actions>
123660 ········</ocil:questionnaire>123660 ········</ocil:questionnaire>
123661 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_ocil:questionnaire:1"> 
123662 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·truncate</ocil:title>123661 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1">
 123662 ··········<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>
123663 ··········<ocil:actions>123663 ··········<ocil:actions>
123664 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_action:testaction:1</ocil:test_action_ref>123664 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>
123665 ··········</ocil:actions>123665 ··········</ocil:actions>
123666 ········</ocil:questionnaire>123666 ········</ocil:questionnaire>
123667 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_banner_enabled_ocil:questionnaire:1"> 
123668 ··········<ocil:title>Enable·GNOME3·Login·Warning·Banner</ocil:title>123667 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_opasswd_ocil:questionnaire:1">
 123668 ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/security/opasswd</ocil:title>
123669 ··········<ocil:actions>123669 ··········<ocil:actions>
123670 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_banner_enabled_action:testaction:1</ocil:test_action_ref>123670 ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_opasswd_action:testaction:1</ocil:test_action_ref>
123671 ··········</ocil:actions>123671 ··········</ocil:actions>
123672 ········</ocil:questionnaire>123672 ········</ocil:questionnaire>
123673 ········<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1"> 
123674 ··········<ocil:title>Set·Lockout·Time·for·Failed·Password·Attempts</ocil:title>123673 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chacl_ocil:questionnaire:1">
 123674 ··········<ocil:title>Record·Any·Attempts·to·Run·chacl</ocil:title>
123675 ··········<ocil:actions>123675 ··········<ocil:actions>
123676 ············<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_unlock_time_action:testaction:1</ocil:test_action_ref>123676 ············<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chacl_action:testaction:1</ocil:test_action_ref>
123677 ··········</ocil:actions>123677 ··········</ocil:actions>
123678 ········</ocil:questionnaire>123678 ········</ocil:questionnaire>
123679 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">123679 ········<ocil:questionnaire·id="ocil:ssg-journald_storage_ocil:questionnaire:1">
Max diff block lines reached; 936070/948481 bytes (98.69%) of diff not shown.
884 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ocil.xml
884 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ocil.xml
Ordering differences only
    
Offset 3, 3943 lines modifiedOffset 3, 3943 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_info_ocil:questionnaire:1">
11 ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>11 ······<ocil:title>Set·LogLevel·to·INFO</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_info_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-service_dovecot_disabled_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_audit_nosuid_ocil:questionnaire:1">
17 ······<ocil:title>Disable·Dovecot·Service</ocil:title>17 ······<ocil:title>Add·nosuid·Option·to·/var/log/audit</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-service_dovecot_disabled_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_nosuid_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">
23 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>23 ······<ocil:title>Verify·Owner·on·crontab</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-package_rsh_removed_ocil:questionnaire:1">
29 ······<ocil:title>Set·SSH·Client·Alive·Interval</ocil:title>29 ······<ocil:title>Uninstall·rsh·Package</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sshd_set_idle_timeout_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-package_rsh_removed_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_yama_ptrace_scope_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">
35 ······<ocil:title>Restrict·usage·of·ptrace·to·descendant·processes</ocil:title>35 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_yama_ptrace_scope_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1"> 
41 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1">
 41 ······<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"> 
47 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_usermod_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·usermod</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_usermod_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minlen_ocil:questionnaire:1">
53 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>53 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Length</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minlen_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_ocil:questionnaire:1"> 
59 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·truncate</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1">
 59 ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_banner_enabled_ocil:questionnaire:1"> 
65 ······<ocil:title>Enable·GNOME3·Login·Warning·Banner</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_opasswd_ocil:questionnaire:1">
 65 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/security/opasswd</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_banner_enabled_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_opasswd_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1"> 
71 ······<ocil:title>Set·Lockout·Time·for·Failed·Password·Attempts</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chacl_ocil:questionnaire:1">
 71 ······<ocil:title>Record·Any·Attempts·to·Run·chacl</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_unlock_time_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chacl_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-journald_storage_ocil:questionnaire:1">
77 ······<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>77 ······<ocil:title>Ensure·journald·is·configured·to·write·log·files·to·persistent·disk</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-journald_storage_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_nodev_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>83 ······<ocil:title>Add·nodev·Option·to·/var/log</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_nodev_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_stig_ocil:questionnaire:1"> 
89 ······<ocil:title>System·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-service_named_disabled_ocil:questionnaire:1">
 89 ······<ocil:title>Disable·named·Service</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_stig_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-service_named_disabled_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_filecreatemode_ocil:questionnaire:1">
95 ······<ocil:title>Verify·Permissions·on·/etc/at.allow·file</ocil:title>95 ······<ocil:title>Ensure·rsyslog·Default·File·Permissions·Configured</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_at_allow_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-rsyslog_filecreatemode_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_rmmod_ocil:questionnaire:1"> 
101 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·rmmod</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nosuid_ocil:questionnaire:1">
 101 ······<ocil:title>Add·nosuid·Option·to·/dev/shm</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_rmmod_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nosuid_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_motd_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1">
107 ······<ocil:title>Verify·permissions·on·Message·of·the·Day·Banner</ocil:title>107 ······<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_motd_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1"> 
113 ······<ocil:title>Limit·Users'·SSH·Access</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_modprobe_ocil:questionnaire:1">
 113 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·modprobe</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_modprobe_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_faillock_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_gshadow_ocil:questionnaire:1">
119 ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·faillock</ocil:title>119 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/gshadow</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_faillock_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_gshadow_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 891976/904596 bytes (98.60%) of diff not shown.
3.72 MB
ssg-debian_0.1.76-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0·····1976·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1980·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0··1230224·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0··1230012·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
3.72 MB
data.tar.xz
3.72 MB
data.tar
734 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
734 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:11">28 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:11">
29 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·11</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·11</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml">oval:ssg-installed_OS_is_debian11:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml">oval:ssg-installed_OS_is_debian11:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Debian·11.·It·is·a·rendering·of40 configuration·settings·for·Debian·11.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 76227, 15 lines modifiedOffset 76227, 15 lines modified
76227 ··············<xccdf-1.2:check-content-ref·href="ssg-debian11-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>76227 ··············<xccdf-1.2:check-content-ref·href="ssg-debian11-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
76228 ············</xccdf-1.2:check>76228 ············</xccdf-1.2:check>
76229 ··········</xccdf-1.2:Rule>76229 ··········</xccdf-1.2:Rule>
76230 ········</xccdf-1.2:Group>76230 ········</xccdf-1.2:Group>
76231 ······</xccdf-1.2:Group>76231 ······</xccdf-1.2:Group>
76232 ····</xccdf-1.2:Benchmark>76232 ····</xccdf-1.2:Benchmark>
76233 ··</ds:component>76233 ··</ds:component>
76234 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-oval.xml"·timestamp="2025-02-28T20:08:00">76234 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-oval.xml"·timestamp="2025-03-01T22:08:00">
76235 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">76235 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
76236 ······<oval-def:generator>76236 ······<oval-def:generator>
76237 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>76237 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
76238 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>76238 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
76239 ········<oval:schema_version>5.11</oval:schema_version>76239 ········<oval:schema_version>5.11</oval:schema_version>
76240 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>76240 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
76241 ······</oval-def:generator>76241 ······</oval-def:generator>
Offset 93180, 2500 lines modifiedOffset 93180, 2500 lines modified
93180 ············</oval-def:arithmetic>93180 ············</oval-def:arithmetic>
93181 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>93181 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
93182 ··········</oval-def:arithmetic>93182 ··········</oval-def:arithmetic>
93183 ········</oval-def:local_variable>93183 ········</oval-def:local_variable>
93184 ······</oval-def:variables>93184 ······</oval-def:variables>
93185 ····</oval-def:oval_definitions>93185 ····</oval-def:oval_definitions>
93186 ··</ds:component>93186 ··</ds:component>
93187 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-ocil.xml"·timestamp="2025-02-28T20:08:00">93187 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-ocil.xml"·timestamp="2025-03-01T22:08:00">
93188 ····<ocil:ocil>93188 ····<ocil:ocil>
93189 ······<ocil:generator>93189 ······<ocil:generator>
93190 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>93190 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
93191 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>93191 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
93192 ········<ocil:schema_version>2.0</ocil:schema_version>93192 ········<ocil:schema_version>2.0</ocil:schema_version>
93193 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>93193 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
93194 ······</ocil:generator>93194 ······</ocil:generator>
93195 ······<ocil:questionnaires>93195 ······<ocil:questionnaires>
93196 ········<ocil:questionnaire·id="ocil:ssg-no_all_squash_exports_ocil:questionnaire:1">93196 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1">
93197 ··········<ocil:title>Ensure·All-Squashing·Disabled·On·All·Exports</ocil:title>93197 ··········<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
93198 ··········<ocil:actions>93198 ··········<ocil:actions>
93199 ············<ocil:test_action_ref>ocil:ssg-no_all_squash_exports_action:testaction:1</ocil:test_action_ref>93199 ············<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
93200 ··········</ocil:actions>93200 ··········</ocil:actions>
93201 ········</ocil:questionnaire>93201 ········</ocil:questionnaire>
93202 ········<ocil:questionnaire·id="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1">93202 ········<ocil:questionnaire·id="ocil:ssg-snmpd_not_default_password_ocil:questionnaire:1">
93203 ··········<ocil:title>Ensure·SMEP·is·not·disabled·during·boot</ocil:title>93203 ··········<ocil:title>Ensure·Default·SNMP·Password·Is·Not·Used</ocil:title>
93204 ··········<ocil:actions>93204 ··········<ocil:actions>
93205 ············<ocil:test_action_ref>ocil:ssg-grub2_nosmep_argument_absent_action:testaction:1</ocil:test_action_ref>93205 ············<ocil:test_action_ref>ocil:ssg-snmpd_not_default_password_action:testaction:1</ocil:test_action_ref>
93206 ··········</ocil:actions>93206 ··········</ocil:actions>
93207 ········</ocil:questionnaire>93207 ········</ocil:questionnaire>
93208 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
93209 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>93208 ········<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
 93209 ··········<ocil:title>Disable·Host-Based·Authentication</ocil:title>
93210 ··········<ocil:actions>93210 ··········<ocil:actions>
93211 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>93211 ············<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
93212 ··········</ocil:actions>93212 ··········</ocil:actions>
93213 ········</ocil:questionnaire>93213 ········</ocil:questionnaire>
93214 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_x86_vsyscall_emulation_ocil:questionnaire:1"> 
93215 ··········<ocil:title>Disable·x86·vsyscall·emulation</ocil:title>93214 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1">
 93215 ··········<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rename</ocil:title>
93216 ··········<ocil:actions>93216 ··········<ocil:actions>
93217 ············<ocil:test_action_ref>ocil:ssg-kernel_config_x86_vsyscall_emulation_action:testaction:1</ocil:test_action_ref>93217 ············<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1</ocil:test_action_ref>
93218 ··········</ocil:actions>93218 ··········</ocil:actions>
93219 ········</ocil:questionnaire>93219 ········</ocil:questionnaire>
93220 ········<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">93220 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1">
93221 ··········<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>93221 ··········<ocil:title>Disable·Kerberos·Authentication</ocil:title>
93222 ··········<ocil:actions>93222 ··········<ocil:actions>
93223 ············<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>93223 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref>
93224 ··········</ocil:actions>93224 ··········</ocil:actions>
93225 ········</ocil:questionnaire>93225 ········</ocil:questionnaire>
93226 ········<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1">93226 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_filter_ocil:questionnaire:1">
93227 ··········<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>93227 ··········<ocil:title>Enable·use·of·Berkeley·Packet·Filter·with·seccomp</ocil:title>
93228 ··········<ocil:actions>93228 ··········<ocil:actions>
93229 ············<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>93229 ············<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_filter_action:testaction:1</ocil:test_action_ref>
93230 ··········</ocil:actions>93230 ··········</ocil:actions>
93231 ········</ocil:questionnaire>93231 ········</ocil:questionnaire>
93232 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1"> 
93233 ··········<ocil:title>Disable·IPv6·Networking·Support·Automatic·Loading</ocil:title>93232 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1">
 93233 ··········<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title>
93234 ··········<ocil:actions>93234 ··········<ocil:actions>
93235 ············<ocil:test_action_ref>ocil:ssg-kernel_module_ipv6_option_disabled_action:testaction:1</ocil:test_action_ref>93235 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
93236 ··········</ocil:actions>93236 ··········</ocil:actions>
93237 ········</ocil:questionnaire>93237 ········</ocil:questionnaire>
93238 ········<ocil:questionnaire·id="ocil:ssg-no_netrc_files_ocil:questionnaire:1">93238 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">
93239 ··········<ocil:title>Verify·No·netrc·Files·Exist</ocil:title>93239 ··········<ocil:title>Enable·support·for·BUG()</ocil:title>
93240 ··········<ocil:actions>93240 ··········<ocil:actions>
93241 ············<ocil:test_action_ref>ocil:ssg-no_netrc_files_action:testaction:1</ocil:test_action_ref>93241 ············<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref>
93242 ··········</ocil:actions>93242 ··········</ocil:actions>
93243 ········</ocil:questionnaire>93243 ········</ocil:questionnaire>
93244 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1">93244 ········<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">
93245 ··········<ocil:title>System·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>93245 ··········<ocil:title>Disable·XDMCP·in·GDM</ocil:title>
93246 ··········<ocil:actions>93246 ··········<ocil:actions>
93247 ············<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>93247 ············<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>
93248 ··········</ocil:actions>93248 ··········</ocil:actions>
93249 ········</ocil:questionnaire>93249 ········</ocil:questionnaire>
93250 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_passwd_ocil:questionnaire:1"> 
93251 ··········<ocil:title>Verify·Group·Who·Owns·Backup·passwd·File</ocil:title>93250 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1">
 93251 ··········<ocil:title>Configure·ARP·filtering·for·All·IPv4·Interfaces</ocil:title>
93252 ··········<ocil:actions>93252 ··········<ocil:actions>
93253 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>93253 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1</ocil:test_action_ref>
93254 ··········</ocil:actions>93254 ··········</ocil:actions>
93255 ········</ocil:questionnaire>93255 ········</ocil:questionnaire>
93256 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">93256 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
93257 ··········<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>93257 ··········<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
93258 ··········<ocil:actions>93258 ··········<ocil:actions>
93259 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>93259 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
93260 ··········</ocil:actions>93260 ··········</ocil:actions>
93261 ········</ocil:questionnaire>93261 ········</ocil:questionnaire>
93262 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_syslog_ocil:questionnaire:1">93262 ········<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1">
Max diff block lines reached; 739712/751665 bytes (98.41%) of diff not shown.
699 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ocil.xml
699 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ocil.xml
Ordering differences only
    
Offset 3, 2491 lines modifiedOffset 3, 2491 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-no_all_squash_exports_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1">
11 ······<ocil:title>Ensure·All-Squashing·Disabled·On·All·Exports</ocil:title>11 ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-no_all_squash_exports_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-snmpd_not_default_password_ocil:questionnaire:1">
17 ······<ocil:title>Ensure·SMEP·is·not·disabled·during·boot</ocil:title>17 ······<ocil:title>Ensure·Default·SNMP·Password·Is·Not·Used</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmep_argument_absent_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-snmpd_not_default_password_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
23 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
 23 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_x86_vsyscall_emulation_ocil:questionnaire:1"> 
29 ······<ocil:title>Disable·x86·vsyscall·emulation</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1">
 29 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rename</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_x86_vsyscall_emulation_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1">
35 ······<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>35 ······<ocil:title>Disable·Kerberos·Authentication</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_filter_ocil:questionnaire:1">
41 ······<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>41 ······<ocil:title>Enable·use·of·Berkeley·Packet·Filter·with·seccomp</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_filter_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1"> 
47 ······<ocil:title>Disable·IPv6·Networking·Support·Automatic·Loading</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1">
 47 ······<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-kernel_module_ipv6_option_disabled_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-no_netrc_files_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">
53 ······<ocil:title>Verify·No·netrc·Files·Exist</ocil:title>53 ······<ocil:title>Enable·support·for·BUG()</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-no_netrc_files_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">
59 ······<ocil:title>System·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>59 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_passwd_ocil:questionnaire:1"> 
65 ······<ocil:title>Verify·Group·Who·Owns·Backup·passwd·File</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1">
 65 ······<ocil:title>Configure·ARP·filtering·for·All·IPv4·Interfaces</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>71 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_syslog_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1">
77 ······<ocil:title>Verify·Permissions·on·/var/log/syslog·File</ocil:title>77 ······<ocil:title>IOMMU·configuration·directive</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_syslog_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-grub2_enable_iommu_force_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ocil:questionnaire:1"> 
83 ······<ocil:title>Ensure·auditd·Collects·Unauthorized·Access·Attempts·to·Files·(unsuccessful)</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1">
 83 ······<ocil:title>Ensure·SELinux·is·Not·Disabled</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-selinux_not_disabled_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1"> 
89 ······<ocil:title>Enforce·Spectre·v2·mitigation</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_gshadow_ocil:questionnaire:1">
 89 ······<ocil:title>Verify·Group·Who·Owns·Backup·gshadow·File</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-grub2_spectre_v2_argument_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_MFEhiplsm_installed_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1">
95 ······<ocil:title>Install·the·Host·Intrusion·Prevention·System·(HIPS)·Module</ocil:title>95 ······<ocil:title>Ensure·logrotate·is·Installed</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_MFEhiplsm_installed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title>101 ······<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_library_dirs_ocil:questionnaire:1"> 
107 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Restrictive·Permissions</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">
 107 ······<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-dir_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1"> 
113 ······<ocil:title>Configure·Polyinstantiation·of·/var/tmp·Directories</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-set_ip6tables_default_rule_ocil:questionnaire:1">
 113 ······<ocil:title>Set·Default·ip6tables·Policy·for·Incoming·Packets</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_var_tmp_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-set_ip6tables_default_rule_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User</ocil:title>119 ······<ocil:title>Verify·Permissions·on·group·File</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_group_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 703452/715679 bytes (98.29%) of diff not shown.
1.19 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ds.xml
1.19 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-oval-definitions-bookworm.xml.bz2"·xlink:href="https://www.debian.org/security/oval/oval-definitions-bookworm.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-oval-definitions-bookworm.xml.bz2"·xlink:href="https://www.debian.org/security/oval/oval-definitions-bookworm.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:12">30 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:12">
31 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·12</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·12</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml">oval:ssg-installed_OS_is_debian12:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml">oval:ssg-installed_OS_is_debian12:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·12</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·12</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Debian·12.·It·is·a·rendering·of42 configuration·settings·for·Debian·12.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 110245, 15 lines modifiedOffset 110245, 15 lines modified
110245 ··············<xccdf-1.2:check-content-ref·href="ssg-debian12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>110245 ··············<xccdf-1.2:check-content-ref·href="ssg-debian12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
110246 ············</xccdf-1.2:check>110246 ············</xccdf-1.2:check>
110247 ··········</xccdf-1.2:Rule>110247 ··········</xccdf-1.2:Rule>
110248 ········</xccdf-1.2:Group>110248 ········</xccdf-1.2:Group>
110249 ······</xccdf-1.2:Group>110249 ······</xccdf-1.2:Group>
110250 ····</xccdf-1.2:Benchmark>110250 ····</xccdf-1.2:Benchmark>
110251 ··</ds:component>110251 ··</ds:component>
110252 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-oval.xml"·timestamp="2025-02-28T20:08:00">110252 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-oval.xml"·timestamp="2025-03-01T22:08:00">
110253 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">110253 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
110254 ······<oval-def:generator>110254 ······<oval-def:generator>
110255 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>110255 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
110256 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>110256 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
110257 ········<oval:schema_version>5.11</oval:schema_version>110257 ········<oval:schema_version>5.11</oval:schema_version>
110258 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>110258 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
110259 ······</oval-def:generator>110259 ······</oval-def:generator>
Offset 140530, 7923 lines modifiedOffset 140530, 7930 lines modified
140530 ············</oval-def:arithmetic>140530 ············</oval-def:arithmetic>
140531 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>140531 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
140532 ··········</oval-def:arithmetic>140532 ··········</oval-def:arithmetic>
140533 ········</oval-def:local_variable>140533 ········</oval-def:local_variable>
140534 ······</oval-def:variables>140534 ······</oval-def:variables>
140535 ····</oval-def:oval_definitions>140535 ····</oval-def:oval_definitions>
140536 ··</ds:component>140536 ··</ds:component>
140537 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-ocil.xml"·timestamp="2025-02-28T20:08:00">140537 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-ocil.xml"·timestamp="2025-03-01T22:08:00">
140538 ····<ocil:ocil>140538 ····<ocil:ocil>
140539 ······<ocil:generator>140539 ······<ocil:generator>
140540 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>140540 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
140541 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>140541 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
140542 ········<ocil:schema_version>2.0</ocil:schema_version>140542 ········<ocil:schema_version>2.0</ocil:schema_version>
140543 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>140543 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
140544 ······</ocil:generator>140544 ······</ocil:generator>
140545 ······<ocil:questionnaires>140545 ······<ocil:questionnaires>
 140546 ········<ocil:questionnaire·id="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1">
 140547 ··········<ocil:title>Ensure·SMAP·is·not·disabled·during·boot</ocil:title>
 140548 ··········<ocil:actions>
 140549 ············<ocil:test_action_ref>ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1</ocil:test_action_ref>
 140550 ··········</ocil:actions>
 140551 ········</ocil:questionnaire>
140546 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1">140552 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1">
140547 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>140553 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>
140548 ··········<ocil:actions>140554 ··········<ocil:actions>
140549 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>140555 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>
140550 ··········</ocil:actions>140556 ··········</ocil:actions>
140551 ········</ocil:questionnaire>140557 ········</ocil:questionnaire>
140552 ········<ocil:questionnaire·id="ocil:ssg-package_sudo_installed_ocil:questionnaire:1">140558 ········<ocil:questionnaire·id="ocil:ssg-dir_system_commands_root_owned_ocil:questionnaire:1">
140553 ··········<ocil:title>Install·sudo·Package</ocil:title>140559 ··········<ocil:title>Verify·that·system·commands·directories·have·root·ownership</ocil:title>
140554 ··········<ocil:actions>140560 ··········<ocil:actions>
140555 ············<ocil:test_action_ref>ocil:ssg-package_sudo_installed_action:testaction:1</ocil:test_action_ref>140561 ············<ocil:test_action_ref>ocil:ssg-dir_system_commands_root_owned_action:testaction:1</ocil:test_action_ref>
140556 ··········</ocil:actions>140562 ··········</ocil:actions>
140557 ········</ocil:questionnaire>140563 ········</ocil:questionnaire>
140558 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_ocil:questionnaire:1"> 
140559 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv6·Interfaces</ocil:title>140564 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1">
 140565 ··········<ocil:title>Disable·SSH·root·Login·with·a·Password·(Insecure)</ocil:title>
140560 ··········<ocil:actions>140566 ··········<ocil:actions>
140561 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>140567 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref>
140562 ··········</ocil:actions>140568 ··········</ocil:actions>
140563 ········</ocil:questionnaire>140569 ········</ocil:questionnaire>
140564 ········<ocil:questionnaire·id="ocil:ssg-coredump_disable_backtraces_ocil:questionnaire:1">140570 ········<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1">
140565 ··········<ocil:title>Disable·core·dump·backtraces</ocil:title>140571 ··········<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title>
140566 ··········<ocil:actions>140572 ··········<ocil:actions>
140567 ············<ocil:test_action_ref>ocil:ssg-coredump_disable_backtraces_action:testaction:1</ocil:test_action_ref>140573 ············<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref>
140568 ··········</ocil:actions>140574 ··········</ocil:actions>
140569 ········</ocil:questionnaire>140575 ········</ocil:questionnaire>
140570 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1">140576 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1">
140571 ··········<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>140577 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title>
140572 ··········<ocil:actions>140578 ··········<ocil:actions>
140573 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref>140579 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref>
140574 ··········</ocil:actions>140580 ··········</ocil:actions>
140575 ········</ocil:questionnaire>140581 ········</ocil:questionnaire>
140576 ········<ocil:questionnaire·id="ocil:ssg-accounts_users_home_files_groupownership_ocil:questionnaire:1">140582 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1">
140577 ··········<ocil:title>All·User·Files·and·Directories·In·The·Home·Directory·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>140583 ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title>
140578 ··········<ocil:actions>140584 ··········<ocil:actions>
140579 ············<ocil:test_action_ref>ocil:ssg-accounts_users_home_files_groupownership_action:testaction:1</ocil:test_action_ref>140585 ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref>
140580 ··········</ocil:actions>140586 ··········</ocil:actions>
140581 ········</ocil:questionnaire>140587 ········</ocil:questionnaire>
140582 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_efi_user_cfg_ocil:questionnaire:1"> 
140583 ··········<ocil:title>Verify·/boot/grub2/user.cfg·Group·Ownership</ocil:title>140588 ········<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1">
 140589 ··········<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>
140584 ··········<ocil:actions>140590 ··········<ocil:actions>
140585 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_efi_user_cfg_action:testaction:1</ocil:test_action_ref>140591 ············<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>
140586 ··········</ocil:actions>140592 ··········</ocil:actions>
140587 ········</ocil:questionnaire>140593 ········</ocil:questionnaire>
140588 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1">140594 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">
140589 ··········<ocil:title>Kernel·panic·oops</ocil:title>140595 ··········<ocil:title>Disable·SSH·Root·Login</ocil:title>
140590 ··········<ocil:actions>140596 ··········<ocil:actions>
140591 ············<ocil:test_action_ref>ocil:ssg-kernel_config_panic_on_oops_action:testaction:1</ocil:test_action_ref>140597 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>
140592 ··········</ocil:actions>140598 ··········</ocil:actions>
140593 ········</ocil:questionnaire>140599 ········</ocil:questionnaire>
140594 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1">140600 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
140595 ··········<ocil:title>Disable·Kerberos·Authentication</ocil:title>140601 ··········<ocil:title>Disable·X11·Forwarding</ocil:title>
140596 ··········<ocil:actions>140602 ··········<ocil:actions>
140597 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref>140603 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
140598 ··········</ocil:actions>140604 ··········</ocil:actions>
140599 ········</ocil:questionnaire>140605 ········</ocil:questionnaire>
140600 ········<ocil:questionnaire·id="ocil:ssg-package_talk-server_removed_ocil:questionnaire:1">140606 ········<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1">
140601 ··········<ocil:title>Uninstall·talk-server·Package</ocil:title>140607 ··········<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>
140602 ··········<ocil:actions>140608 ··········<ocil:actions>
140603 ············<ocil:test_action_ref>ocil:ssg-package_talk-server_removed_action:testaction:1</ocil:test_action_ref>140609 ············<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>
140604 ··········</ocil:actions>140610 ··········</ocil:actions>
140605 ········</ocil:questionnaire>140611 ········</ocil:questionnaire>
140606 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_shadow_ocil:questionnaire:1"> 
140607 ··········<ocil:title>Verify·User·Who·Owns·Backup·shadow·File</ocil:title>140612 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1">
 140613 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmod</ocil:title>
Max diff block lines reached; 1232090/1243917 bytes (99.05%) of diff not shown.
1.13 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ocil.xml
1.13 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ocil.xml
Ordering differences only
    
Offset 3, 7914 lines modifiedOffset 3, 7921 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
 10 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·SMAP·is·not·disabled·during·boot</ocil:title>
 12 ······<ocil:actions>
 13 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1</ocil:test_action_ref>
 14 ······</ocil:actions>
 15 ····</ocil:questionnaire>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1">
11 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>17 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>
12 ······<ocil:actions>18 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>20 ······</ocil:actions>
15 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-package_sudo_installed_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-dir_system_commands_root_owned_ocil:questionnaire:1">
17 ······<ocil:title>Install·sudo·Package</ocil:title>23 ······<ocil:title>Verify·that·system·commands·directories·have·root·ownership</ocil:title>
18 ······<ocil:actions>24 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_sudo_installed_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-dir_system_commands_root_owned_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>26 ······</ocil:actions>
21 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_ocil:questionnaire:1"> 
23 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv6·Interfaces</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1">
 29 ······<ocil:title>Disable·SSH·root·Login·with·a·Password·(Insecure)</ocil:title>
24 ······<ocil:actions>30 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>32 ······</ocil:actions>
27 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-coredump_disable_backtraces_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1">
29 ······<ocil:title>Disable·core·dump·backtraces</ocil:title>35 ······<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title>
30 ······<ocil:actions>36 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-coredump_disable_backtraces_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>38 ······</ocil:actions>
33 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1"> 
35 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1">
 41 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title>
36 ······<ocil:actions>42 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>44 ······</ocil:actions>
39 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-accounts_users_home_files_groupownership_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1">
41 ······<ocil:title>All·User·Files·and·Directories·In·The·Home·Directory·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>47 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title>
42 ······<ocil:actions>48 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-accounts_users_home_files_groupownership_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>50 ······</ocil:actions>
45 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_efi_user_cfg_ocil:questionnaire:1"> 
47 ······<ocil:title>Verify·/boot/grub2/user.cfg·Group·Ownership</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1">
 53 ······<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>
48 ······<ocil:actions>54 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_efi_user_cfg_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>56 ······</ocil:actions>
51 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">
53 ······<ocil:title>Kernel·panic·oops</ocil:title>59 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>
54 ······<ocil:actions>60 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_on_oops_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>62 ······</ocil:actions>
57 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
59 ······<ocil:title>Disable·Kerberos·Authentication</ocil:title>65 ······<ocil:title>Disable·X11·Forwarding</ocil:title>
60 ······<ocil:actions>66 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>68 ······</ocil:actions>
63 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-package_talk-server_removed_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1">
65 ······<ocil:title>Uninstall·talk-server·Package</ocil:title>71 ······<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>
66 ······<ocil:actions>72 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-package_talk-server_removed_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>74 ······</ocil:actions>
69 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_shadow_ocil:questionnaire:1"> 
71 ······<ocil:title>Verify·User·Who·Owns·Backup·shadow·File</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1">
 77 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmod</ocil:title>
72 ······<ocil:actions>78 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmod_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>80 ······</ocil:actions>
75 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1"> 
77 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_syslog_ocil:questionnaire:1">
 83 ······<ocil:title>Verify·Permissions·on·/var/log/syslog·File</ocil:title>
78 ······<ocil:actions>84 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_syslog_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>86 ······</ocil:actions>
81 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-apparmor_configured_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·AppArmor·is·Active·and·Configured</ocil:title>89 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title>
84 ······<ocil:actions>90 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-apparmor_configured_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>92 ······</ocil:actions>
87 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_ocil:questionnaire:1"> 
89 ······<ocil:title>Limit·CPU·consumption·of·the·Perf·system</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1">
 95 ······<ocil:title>Ensure·gnutls-utils·is·installed</ocil:title>
90 ······<ocil:actions>96 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>98 ······</ocil:actions>
93 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_talk_removed_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1">
95 ······<ocil:title>Uninstall·talk·Package</ocil:title>101 ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>
96 ······<ocil:actions>102 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_talk_removed_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>104 ······</ocil:actions>
99 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_reboot_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_tallylog_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·reboot</ocil:title>107 ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·tallylog</ocil:title>
102 ······<ocil:actions>108 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_reboot_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_tallylog_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>110 ······</ocil:actions>
105 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1">
107 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>113 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Different·Categories</ocil:title>
108 ······<ocil:actions>114 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minclass_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>116 ······</ocil:actions>
111 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1">
113 ······<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>119 ······<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title>
114 ······<ocil:actions>120 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>122 ······</ocil:actions>
117 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
Max diff block lines reached; 1174183/1186571 bytes (98.96%) of diff not shown.
79.7 MB
ssg-nondebian_0.1.76-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0····18196·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0····18204·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0·37082368·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0·37082148·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
79.7 MB
data.tar.xz
79.7 MB
data.tar
3.5 KB
./usr/share/doc/ssg-nondebian/table-ol7-nistrefs-stig_gui.html
    
Offset 8560, 18 lines modifiedOffset 8560, 18 lines modified
000216f0:·6b0a·616e·6420·7573·6520·7468·6520·696e··k.and·use·the·in000216f0:·6b0a·616e·6420·7573·6520·7468·6520·696e··k.and·use·the·in
00021700:·666f·726d·6174·696f·6e20·746f·2070·6f74··formation·to·pot00021700:·666f·726d·6174·696f·6e20·746f·2070·6f74··formation·to·pot
00021710:·656e·7469·616c·6c79·2063·6f6d·7072·6f6d··entially·comprom00021710:·656e·7469·616c·6c79·2063·6f6d·7072·6f6d··entially·comprom
00021720:·6973·6520·7468·6520·696e·7465·6772·6974··ise·the·integrit00021720:·6973·6520·7468·6520·696e·7465·6772·6974··ise·the·integrit
00021730:·7920·6f66·2074·6865·2073·7973·7465·6d20··y·of·the·system·00021730:·7920·6f66·2074·6865·2073·7973·7465·6d20··y·of·the·system·
00021740:·616e·640a·6e65·7477·6f72·6b28·7329·2e0a··and.network(s)..00021740:·616e·640a·6e65·7477·6f72·6b28·7329·2e0a··and.network(s)..
00021750:·2020·3c2f·7464·3e0a·2020·3c74·643e·7661····</td>.··<td>va00021750:·2020·3c2f·7464·3e0a·2020·3c74·643e·7661····</td>.··<td>va
00021760:·725f·736e·6d70·645f·7277·5f73·7472·696e··r_snmpd_rw_strin00021760:·725f·736e·6d70·645f·726f·5f73·7472·696e··r_snmpd_ro_strin
00021770:·673d·6368·616e·6765·6d65·7277·3c62·722f··g=changemerw<br/00021770:·673d·6368·616e·6765·6d65·726f·3c62·722f··g=changemero<br/
00021780:·3e76·6172·5f73·6e6d·7064·5f72·6f5f·7374··>var_snmpd_ro_st00021780:·3e76·6172·5f73·6e6d·7064·5f72·775f·7374··>var_snmpd_rw_st
00021790:·7269·6e67·3d63·6861·6e67·656d·6572·6f3c··ring=changemero<00021790:·7269·6e67·3d63·6861·6e67·656d·6572·773c··ring=changemerw<
000217a0:·2f74·643e·0a3c·2f74·723e·0a3c·7472·3e0a··/td>.</tr>.<tr>.000217a0:·2f74·643e·0a3c·2f74·723e·0a3c·7472·3e0a··/td>.</tr>.<tr>.
000217b0:·2020·3c74·643e·5343·2d35·3c2f·7464·3e0a····<td>SC-5</td>.000217b0:·2020·3c74·643e·5343·2d35·3c2f·7464·3e0a····<td>SC-5</td>.
000217c0:·2020·3c74·643e·4e2f·413c·2f74·643e·0a20····<td>N/A</td>.·000217c0:·2020·3c74·643e·4e2f·413c·2f74·643e·0a20····<td>N/A</td>.·
000217d0:·203c·7464·3e43·6f6e·6669·6775·7265·204b···<td>Configure·K000217d0:·203c·7464·3e43·6f6e·6669·6775·7265·204b···<td>Configure·K
000217e0:·6572·6e65·6c20·746f·2052·6174·6520·4c69··ernel·to·Rate·Li000217e0:·6572·6e65·6c20·746f·2052·6174·6520·4c69··ernel·to·Rate·Li
000217f0:·6d69·7420·5365·6e64·696e·6720·6f66·2044··mit·Sending·of·D000217f0:·6d69·7420·5365·6e64·696e·6720·6f66·2044··mit·Sending·of·D
00021800:·7570·6c69·6361·7465·2054·4350·2041·636b··uplicate·TCP·Ack00021800:·7570·6c69·6361·7465·2054·4350·2041·636b··uplicate·TCP·Ack
1.87 KB
html2text {}
    
Offset 2919, 16 lines modifiedOffset 2919, 16 lines modified
2919 ··············································································network·management2919 ··············································································network·management
2920 ··············································································protocol·(SNMP)2920 ··············································································protocol·(SNMP)
2921 ··············································································community·strings2921 ··············································································community·strings
2922 ··············································································must·be·changed·to2922 ··············································································must·be·changed·to
2923 ··································Edit·/etc/snmp/snmpd.conf,·remove·or·change·maintain·security.2923 ··································Edit·/etc/snmp/snmpd.conf,·remove·or·change·maintain·security.
2924 ··································the·default·community·strings·of·public·and·If·the·service·is2924 ··································the·default·community·strings·of·public·and·If·the·service·is
2925 ··································private.·This·profile·configures·new·read-··running·with·the2925 ··································private.·This·profile·configures·new·read-··running·with·the
2926 ········N/·Ensure·Default·SNMP····only·community·string·to·changemero·and·····default·············var_snmpd_rw_string=changemerw2926 ········N/·Ensure·Default·SNMP····only·community·string·to·changemero·and·····default·············var_snmpd_ro_string=changemero
2927 IA-5(e)·A··Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·····var_snmpd_ro_string=changemero2927 IA-5(e)·A··Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·····var_snmpd_rw_string=changemerw
2928 ··································Once·the·default·community·strings·have·····then·anyone·can2928 ··································Once·the·default·community·strings·have·····then·anyone·can
2929 ··································been·changed,·restart·the·SNMP·service:·····gather·data·about2929 ··································been·changed,·restart·the·SNMP·service:·····gather·data·about
2930 ··································$·sudo·systemctl·restart·snmpd··············the·system·and·the2930 ··································$·sudo·systemctl·restart·snmpd··············the·system·and·the
2931 ··············································································network·and·use·the2931 ··············································································network·and·use·the
2932 ··············································································information·to2932 ··············································································information·to
2933 ··············································································potentially2933 ··············································································potentially
2934 ··············································································compromise·the2934 ··············································································compromise·the
6.32 KB
./usr/share/doc/ssg-nondebian/table-ol8-nistrefs-ospp.html
    
Offset 4070, 15 lines modifiedOffset 4070, 15 lines modified
4070 <tt>RekeyLimit</tt>.4070 <tt>RekeyLimit</tt>.
4071 ··</td>4071 ··</td>
4072 ··<td·xml:lang="en-US">4072 ··<td·xml:lang="en-US">
4073 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4073 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4074 time-based·limit,·effects·of·potential·attacks·against4074 time-based·limit,·effects·of·potential·attacks·against
4075 encryption·keys·are·limited.4075 encryption·keys·are·limited.
4076 ··</td>4076 ··</td>
4077 ··<td>var_ssh_client_rekey_limit_time=1hour<br/>var_ssh_client_rekey_limit_size=1G</td>4077 ··<td>var_ssh_client_rekey_limit_size=1G<br/>var_ssh_client_rekey_limit_time=1hour</td>
4078 </tr>4078 </tr>
4079 <tr>4079 <tr>
4080 ··<td></td>4080 ··<td></td>
4081 ··<td>N/A</td>4081 ··<td>N/A</td>
4082 ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td>4082 ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td>
4083 ··<td·xml:lang="en-US">4083 ··<td·xml:lang="en-US">
4084 To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure4084 To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure
Offset 4133, 15 lines modifiedOffset 4133, 15 lines modified
4133 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>4133 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>
4134 ··</td>4134 ··</td>
4135 ··<td·xml:lang="en-US">4135 ··<td·xml:lang="en-US">
4136 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4136 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4137 time-based·limit,·effects·of·potential·attacks·against4137 time-based·limit,·effects·of·potential·attacks·against
4138 encryption·keys·are·limited.4138 encryption·keys·are·limited.
4139 ··</td>4139 ··</td>
4140 ··<td>var_rekey_limit_time=1hour<br/>var_rekey_limit_size=1G</td>4140 ··<td>var_rekey_limit_size=1G<br/>var_rekey_limit_time=1hour</td>
4141 </tr>4141 </tr>
4142 <tr>4142 <tr>
4143 ··<td></td>4143 ··<td></td>
4144 ··<td>N/A</td>4144 ··<td>N/A</td>
4145 ··<td>SSH·server·uses·strong·entropy·to·seed</td>4145 ··<td>SSH·server·uses·strong·entropy·to·seed</td>
4146 ··<td·xml:lang="en-US">4146 ··<td·xml:lang="en-US">
4147 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.4147 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.
4.98 KB
html2text {}
    
Offset 3341, 16 lines modifiedOffset 3341, 16 lines modified
3341 ··················································································································options,·which·can3341 ··················································································································options,·which·can
3342 ··················································································································help·protect3342 ··················································································································help·protect
3343 ··················································································································programs·which·use3343 ··················································································································programs·which·use
3344 ··················································································································it.3344 ··················································································································it.
3345 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the3345 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the
3346 ·························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the3346 ·························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the
3347 ········Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and3347 ········Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and
3348 ·····N/·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_time=1hour3348 ·····N/·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_size=1G
3349 ·····A··renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_size=1G3349 ·····A··renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_time=1hour
3350 ········for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks3350 ········for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks
3351 ·························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption3351 ·························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption
3352 ·························containing·definition·of·RekeyLimit.·····················································keys·are·limited.3352 ·························containing·definition·of·RekeyLimit.·····················································keys·are·limited.
3353 ··················································································································Some·SSH3353 ··················································································································Some·SSH
3354 ··················································································································implementations·use3354 ··················································································································implementations·use
3355 ··················································································································the·openssl·library3355 ··················································································································the·openssl·library
3356 ··················································································································for·entropy,·which3356 ··················································································································for·entropy,·which
Offset 3401, 16 lines modifiedOffset 3401, 16 lines modified
3401 ··················································································································generator·used·by3401 ··················································································································generator·used·by
3402 ··················································································································SSH·would·be·known3402 ··················································································································SSH·would·be·known
3403 ··················································································································to·potential3403 ··················································································································to·potential
3404 ··················································································································attackers.3404 ··················································································································attackers.
3405 ··················································································································By·decreasing·the3405 ··················································································································By·decreasing·the
3406 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the3406 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the
3407 ········Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and3407 ········Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and
3408 ·····N/·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_time=1hour3408 ·····N/·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_size=1G
3409 ·····A··renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_size=1G3409 ·····A··renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_time=1hour
3410 ·························RekeyLimit·1G·1hour······································································potential·attacks3410 ·························RekeyLimit·1G·1hour······································································potential·attacks
3411 ··················································································································against·encryption3411 ··················································································································against·encryption
3412 ··················································································································keys·are·limited.3412 ··················································································································keys·are·limited.
3413 ··················································································································SSH·implementation3413 ··················································································································SSH·implementation
3414 ··················································································································in·Oracle·Linux·83414 ··················································································································in·Oracle·Linux·8
3415 ··················································································································uses·the·openssl3415 ··················································································································uses·the·openssl
3416 ··················································································································library,·which3416 ··················································································································library,·which
6.48 KB
./usr/share/doc/ssg-nondebian/table-rhel8-nistrefs-ospp.html
    
Offset 4075, 15 lines modifiedOffset 4075, 15 lines modified
4075 <tt>RekeyLimit</tt>.4075 <tt>RekeyLimit</tt>.
4076 ··</td>4076 ··</td>
4077 ··<td·xml:lang="en-US">4077 ··<td·xml:lang="en-US">
4078 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4078 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4079 time-based·limit,·effects·of·potential·attacks·against4079 time-based·limit,·effects·of·potential·attacks·against
4080 encryption·keys·are·limited.4080 encryption·keys·are·limited.
4081 ··</td>4081 ··</td>
4082 ··<td>var_ssh_client_rekey_limit_size=1G<br/>var_ssh_client_rekey_limit_time=1hour</td>4082 ··<td>var_ssh_client_rekey_limit_time=1hour<br/>var_ssh_client_rekey_limit_size=1G</td>
4083 </tr>4083 </tr>
4084 <tr>4084 <tr>
4085 ··<td></td>4085 ··<td></td>
4086 ··<td>CCE-83349-1</td>4086 ··<td>CCE-83349-1</td>
4087 ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td>4087 ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td>
4088 ··<td·xml:lang="en-US">4088 ··<td·xml:lang="en-US">
4089 To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure4089 To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure
Offset 4138, 15 lines modifiedOffset 4138, 15 lines modified
4138 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>4138 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>
4139 ··</td>4139 ··</td>
4140 ··<td·xml:lang="en-US">4140 ··<td·xml:lang="en-US">
4141 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4141 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4142 time-based·limit,·effects·of·potential·attacks·against4142 time-based·limit,·effects·of·potential·attacks·against
4143 encryption·keys·are·limited.4143 encryption·keys·are·limited.
4144 ··</td>4144 ··</td>
4145 ··<td>var_rekey_limit_time=1hour<br/>var_rekey_limit_size=1G</td>4145 ··<td>var_rekey_limit_size=1G<br/>var_rekey_limit_time=1hour</td>
4146 </tr>4146 </tr>
4147 <tr>4147 <tr>
4148 ··<td></td>4148 ··<td></td>
4149 ··<td>CCE-82462-3</td>4149 ··<td>CCE-82462-3</td>
4150 ··<td>SSH·server·uses·strong·entropy·to·seed</td>4150 ··<td>SSH·server·uses·strong·entropy·to·seed</td>
4151 ··<td·xml:lang="en-US">4151 ··<td·xml:lang="en-US">
4152 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.4152 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.
5.11 KB
html2text {}
    
Offset 3356, 16 lines modifiedOffset 3356, 16 lines modified
3356 ······················································································································options,·which·can3356 ······················································································································options,·which·can
3357 ······················································································································help·protect3357 ······················································································································help·protect
3358 ······················································································································programs·which·use3358 ······················································································································programs·which·use
3359 ······················································································································it.3359 ······················································································································it.
3360 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the3360 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the
3361 ·····························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the3361 ·····························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the
3362 ·····CCE-···Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and3362 ·····CCE-···Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and
3363 ·····82880-·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_size=1G3363 ·····82880-·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_time=1hour
3364 ·····6······renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_time=1hour3364 ·····6······renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_size=1G
3365 ············for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks3365 ············for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks
3366 ·····························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption3366 ·····························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption
3367 ·····························containing·definition·of·RekeyLimit.·····················································keys·are·limited.3367 ·····························containing·definition·of·RekeyLimit.·····················································keys·are·limited.
3368 ······················································································································Some·SSH3368 ······················································································································Some·SSH
3369 ······················································································································implementations·use3369 ······················································································································implementations·use
3370 ······················································································································the·openssl·library3370 ······················································································································the·openssl·library
3371 ······················································································································for·entropy,·which3371 ······················································································································for·entropy,·which
Offset 3416, 16 lines modifiedOffset 3416, 16 lines modified
3416 ······················································································································generator·used·by3416 ······················································································································generator·used·by
3417 ······················································································································SSH·would·be·known3417 ······················································································································SSH·would·be·known
3418 ······················································································································to·potential3418 ······················································································································to·potential
3419 ······················································································································attackers.3419 ······················································································································attackers.
3420 ······················································································································By·decreasing·the3420 ······················································································································By·decreasing·the
3421 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the3421 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the
3422 ·····CCE-···Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and3422 ·····CCE-···Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and
3423 ·····82177-·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_time=1hour3423 ·····82177-·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_size=1G
3424 ·····7······renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_size=1G3424 ·····7······renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_time=1hour
3425 ·····························RekeyLimit·1G·1hour······································································potential·attacks3425 ·····························RekeyLimit·1G·1hour······································································potential·attacks
3426 ······················································································································against·encryption3426 ······················································································································against·encryption
3427 ······················································································································keys·are·limited.3427 ······················································································································keys·are·limited.
3428 ······················································································································SSH·implementation3428 ······················································································································SSH·implementation
3429 ······················································································································in·Red·Hat3429 ······················································································································in·Red·Hat
3430 ······················································································································Enterprise·Linux·83430 ······················································································································Enterprise·Linux·8
3431 ······················································································································uses·the·openssl3431 ······················································································································uses·the·openssl
1.31 KB
./usr/share/scap-security-guide/tailoring/ol8_stig_delta_tailoring.xml
1.18 KB
./usr/share/scap-security-guide/tailoring/ol8_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2025-02-28T20:08:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Oracle·Linux·8</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Oracle·Linux·8</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Oracle·Linux·8·V2R3.</xccdf-1.2:description>7 DISA·STIG·for·Oracle·Linux·8·V2R3.</xccdf-1.2:description>
8 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs"·selected="false"/>8 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs"·selected="false"/>
9 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay"·selected="false"/>9 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay"·selected="false"/>
10 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions"·selected="false"/>10 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions"·selected="false"/>
1.12 KB
./usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml
999 B
./usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2025-02-28T20:08:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V2R2.7 DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V2R2.
  
8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·this8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·this
9 configuration·baseline·is·applicable·to·the·operating·system·tier·of9 configuration·baseline·is·applicable·to·the·operating·system·tier·of
1.12 KB
./usr/share/scap-security-guide/tailoring/rhel9_stig_delta_tailoring.xml
999 B
./usr/share/scap-security-guide/tailoring/rhel9_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2025-02-28T20:08:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Red·Hat·Enterprise·Linux·9·V2R3.7 DISA·STIG·for·Red·Hat·Enterprise·Linux·9·V2R3.
  
8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·9,·this8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·9,·this
9 configuration·baseline·is·applicable·to·the·operating·system·tier·of9 configuration·baseline·is·applicable·to·the·operating·system·tier·of
755 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ds.xml
755 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:amazon_linux:2023">28 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:amazon_linux:2023">
29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Linux·2023</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Linux·2023</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml">oval:ssg-installed_OS_is_al2023:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml">oval:ssg-installed_OS_is_al2023:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_AL-2023"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_AL-2023"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Linux·2023</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Linux·2023</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Amazon·Linux·2023.·It·is·a·rendering·of40 configuration·settings·for·Amazon·Linux·2023.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 98811, 15 lines modifiedOffset 98811, 15 lines modified
98811 ··············<xccdf-1.2:check-content-ref·href="ssg-al2023-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/>98811 ··············<xccdf-1.2:check-content-ref·href="ssg-al2023-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/>
98812 ············</xccdf-1.2:check>98812 ············</xccdf-1.2:check>
98813 ··········</xccdf-1.2:Rule>98813 ··········</xccdf-1.2:Rule>
98814 ········</xccdf-1.2:Group>98814 ········</xccdf-1.2:Group>
98815 ······</xccdf-1.2:Group>98815 ······</xccdf-1.2:Group>
98816 ····</xccdf-1.2:Benchmark>98816 ····</xccdf-1.2:Benchmark>
98817 ··</ds:component>98817 ··</ds:component>
98818 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-oval.xml"·timestamp="2025-02-28T20:08:00">98818 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-oval.xml"·timestamp="2025-03-01T22:08:00">
98819 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">98819 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
98820 ······<oval-def:generator>98820 ······<oval-def:generator>
98821 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>98821 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
98822 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>98822 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
98823 ········<oval:schema_version>5.11</oval:schema_version>98823 ········<oval:schema_version>5.11</oval:schema_version>
98824 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>98824 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
98825 ······</oval-def:generator>98825 ······</oval-def:generator>
Offset 117150, 3096 lines modifiedOffset 117150, 3096 lines modified
117150 ············</oval-def:arithmetic>117150 ············</oval-def:arithmetic>
117151 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>117151 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
117152 ··········</oval-def:arithmetic>117152 ··········</oval-def:arithmetic>
117153 ········</oval-def:local_variable>117153 ········</oval-def:local_variable>
117154 ······</oval-def:variables>117154 ······</oval-def:variables>
117155 ····</oval-def:oval_definitions>117155 ····</oval-def:oval_definitions>
117156 ··</ds:component>117156 ··</ds:component>
117157 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-ocil.xml"·timestamp="2025-02-28T20:08:00">117157 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-ocil.xml"·timestamp="2025-03-01T22:08:00">
117158 ····<ocil:ocil>117158 ····<ocil:ocil>
117159 ······<ocil:generator>117159 ······<ocil:generator>
117160 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>117160 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
117161 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>117161 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
117162 ········<ocil:schema_version>2.0</ocil:schema_version>117162 ········<ocil:schema_version>2.0</ocil:schema_version>
117163 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>117163 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
117164 ······</ocil:generator>117164 ······</ocil:generator>
117165 ······<ocil:questionnaires>117165 ······<ocil:questionnaires>
117166 ········<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_logindefs_ocil:questionnaire:1">117166 ········<ocil:questionnaire·id="ocil:ssg-accounts_set_post_pw_existing_ocil:questionnaire:1">
 117167 ··········<ocil:title>Set·existing·passwords·a·period·of·inactivity·before·they·been·locked</ocil:title>
117167 ··········<ocil:title>Set·Password·Hashing·Algorithm·in·/etc/login.defs</ocil:title> 
117168 ··········<ocil:actions> 
117169 ············<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_logindefs_action:testaction:1</ocil:test_action_ref> 
117170 ··········</ocil:actions> 
117171 ········</ocil:questionnaire> 
117172 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1"> 
117173 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title> 
117174 ··········<ocil:actions>117168 ··········<ocil:actions>
117175 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>117169 ············<ocil:test_action_ref>ocil:ssg-accounts_set_post_pw_existing_action:testaction:1</ocil:test_action_ref>
117176 ··········</ocil:actions>117170 ··········</ocil:actions>
117177 ········</ocil:questionnaire>117171 ········</ocil:questionnaire>
117178 ········<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1">117172 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_home_directories_ocil:questionnaire:1">
117179 ··········<ocil:title>Ensure·that·/etc/at.deny·does·not·exist</ocil:title>117173 ··········<ocil:title>All·Interactive·User·Home·Directories·Must·Have·mode·0750·Or·Less·Permissive</ocil:title>
117180 ··········<ocil:actions>117174 ··········<ocil:actions>
117181 ············<ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>117175 ············<ocil:test_action_ref>ocil:ssg-file_permissions_home_directories_action:testaction:1</ocil:test_action_ref>
117182 ··········</ocil:actions>117176 ··········</ocil:actions>
117183 ········</ocil:questionnaire>117177 ········</ocil:questionnaire>
117184 ········<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">117178 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">
117185 ··········<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>117179 ··········<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>
117186 ··········<ocil:actions>117180 ··········<ocil:actions>
117187 ············<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>117181 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>
117188 ··········</ocil:actions>117182 ··········</ocil:actions>
117189 ········</ocil:questionnaire>117183 ········</ocil:questionnaire>
117190 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1"> 
117191 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>117184 ········<ocil:questionnaire·id="ocil:ssg-package_cyrus-imapd_removed_ocil:questionnaire:1">
 117185 ··········<ocil:title>Uninstall·cyrus-imapd·Package</ocil:title>
117192 ··········<ocil:actions>117186 ··········<ocil:actions>
117193 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref>117187 ············<ocil:test_action_ref>ocil:ssg-package_cyrus-imapd_removed_action:testaction:1</ocil:test_action_ref>
117194 ··········</ocil:actions>117188 ··········</ocil:actions>
117195 ········</ocil:questionnaire>117189 ········</ocil:questionnaire>
117196 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1"> 
117197 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·creat</ocil:title>117190 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1">
 117191 ··········<ocil:title>Verify·Group·Ownership·of·Message·of·the·Day·Banner</ocil:title>
117198 ··········<ocil:actions>117192 ··········<ocil:actions>
117199 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref>117193 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref>
117200 ··········</ocil:actions>117194 ··········</ocil:actions>
117201 ········</ocil:questionnaire>117195 ········</ocil:questionnaire>
117202 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1">117196 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_shadow_ocil:questionnaire:1">
117203 ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title>117197 ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/shadow</ocil:title>
117204 ··········<ocil:actions>117198 ··········<ocil:actions>
117205 ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref>117199 ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_shadow_action:testaction:1</ocil:test_action_ref>
117206 ··········</ocil:actions>117200 ··········</ocil:actions>
117207 ········</ocil:questionnaire>117201 ········</ocil:questionnaire>
117208 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1"> 
117209 ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>117202 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">
 117203 ··········<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title>
117210 ··········<ocil:actions>117204 ··········<ocil:actions>
117211 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>117205 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>
117212 ··········</ocil:actions>117206 ··········</ocil:actions>
117213 ········</ocil:questionnaire>117207 ········</ocil:questionnaire>
117214 ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_nodev_ocil:questionnaire:1">117208 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1">
117215 ··········<ocil:title>Add·nodev·Option·to·/var/log</ocil:title>117209 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
117216 ··········<ocil:actions>117210 ··········<ocil:actions>
117217 ············<ocil:test_action_ref>ocil:ssg-mount_option_var_log_nodev_action:testaction:1</ocil:test_action_ref>117211 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref>
117218 ··········</ocil:actions>117212 ··········</ocil:actions>
117219 ········</ocil:questionnaire>117213 ········</ocil:questionnaire>
117220 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_d_ocil:questionnaire:1"> 
117221 ··········<ocil:title>Verify·Owner·on·cron.d</ocil:title>117214 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_admin_space_left_action_ocil:questionnaire:1">
 117215 ··········<ocil:title>Configure·auditd·admin_space_left·Action·on·Low·Disk·Space</ocil:title>
117222 ··········<ocil:actions>117216 ··········<ocil:actions>
117223 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_d_action:testaction:1</ocil:test_action_ref>117217 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_admin_space_left_action_action:testaction:1</ocil:test_action_ref>
117224 ··········</ocil:actions>117218 ··········</ocil:actions>
117225 ········</ocil:questionnaire>117219 ········</ocil:questionnaire>
117226 ········<ocil:questionnaire·id="ocil:ssg-account_unique_name_ocil:questionnaire:1">117220 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1">
117227 ··········<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·Names</ocil:title>117221 ··········<ocil:title>Verify·Group·Who·Owns·cron.hourly</ocil:title>
117228 ··········<ocil:actions>117222 ··········<ocil:actions>
117229 ············<ocil:test_action_ref>ocil:ssg-account_unique_name_action:testaction:1</ocil:test_action_ref>117223 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref>
117230 ··········</ocil:actions>117224 ··········</ocil:actions>
117231 ········</ocil:questionnaire>117225 ········</ocil:questionnaire>
Max diff block lines reached; 760968/773083 bytes (98.43%) of diff not shown.
719 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ocil.xml
719 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ocil.xml
Ordering differences only
    
Offset 3, 3087 lines modifiedOffset 3, 3087 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
 10 ····<ocil:questionnaire·id="ocil:ssg-accounts_set_post_pw_existing_ocil:questionnaire:1">
 11 ······<ocil:title>Set·existing·passwords·a·period·of·inactivity·before·they·been·locked</ocil:title>
10 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_logindefs_ocil:questionnaire:1"> 
11 ······<ocil:title>Set·Password·Hashing·Algorithm·in·/etc/login.defs</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_logindefs_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1"> 
17 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-accounts_set_post_pw_existing_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_home_directories_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·that·/etc/at.deny·does·not·exist</ocil:title>17 ······<ocil:title>All·Interactive·User·Home·Directories·Must·Have·mode·0750·Or·Less·Permissive</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_home_directories_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>23 ······<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1"> 
35 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-package_cyrus-imapd_removed_ocil:questionnaire:1">
 29 ······<ocil:title>Uninstall·cyrus-imapd·Package</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-package_cyrus-imapd_removed_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1"> 
41 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·creat</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1">
 35 ······<ocil:title>Verify·Group·Ownership·of·Message·of·the·Day·Banner</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_shadow_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title>41 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/shadow</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_shadow_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1"> 
53 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">
 47 ······<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_nodev_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1">
59 ······<ocil:title>Add·nodev·Option·to·/var/log</ocil:title>53 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_nodev_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_d_ocil:questionnaire:1"> 
65 ······<ocil:title>Verify·Owner·on·cron.d</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_admin_space_left_action_ocil:questionnaire:1">
 59 ······<ocil:title>Configure·auditd·admin_space_left·Action·on·Low·Disk·Space</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_d_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_admin_space_left_action_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-account_unique_name_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·Names</ocil:title>65 ······<ocil:title>Verify·Group·Who·Owns·cron.hourly</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-account_unique_name_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1"> 
77 ······<ocil:title>Ensure·all·users·last·password·change·date·is·in·the·past</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-sudo_require_reauthentication_ocil:questionnaire:1">
 71 ······<ocil:title>Require·Re-Authentication·When·Using·the·sudo·Command</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sudo_require_reauthentication_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minlen_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Length</ocil:title>77 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minlen_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1"> 
89 ······<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1">
 83 ······<ocil:title>Ensure·LDAP·client·is·not·installed</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-package_openldap-clients_removed_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_private_key_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1">
95 ······<ocil:title>Verify·Permissions·on·SSH·Server·Private·*_key·Key·Files</ocil:title>89 ······<ocil:title>Set·SSH·Client·Alive·Interval</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_private_key_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sshd_set_idle_timeout_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-aide_build_database_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">
101 ······<ocil:title>Build·and·Test·AIDE·Database</ocil:title>95 ······<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-aide_build_database_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-journald_compress_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·journald·is·configured·to·compress·large·log·files</ocil:title>101 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv4·Interfaces</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-journald_compress_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sudo_require_reauthentication_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_net_ocil:questionnaire:1">
113 ······<ocil:title>Require·Re-Authentication·When·Using·the·sudo·Command</ocil:title>107 ······<ocil:title>Modify·the·System·Login·Banner·for·Remote·Connections</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sudo_require_reauthentication_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_net_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_motd_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-aide_check_audit_tools_ocil:questionnaire:1">
119 ······<ocil:title>Verify·ownership·of·Message·of·the·Day·Banner</ocil:title>113 ······<ocil:title>Configure·AIDE·to·Verify·the·Audit·Tools</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_motd_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-aide_check_audit_tools_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 723722/736089 bytes (98.32%) of diff not shown.
897 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds.xml
897 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:2">28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:2">
29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·2</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·2</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml">oval:ssg-installed_OS_is_alinux2:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml">oval:ssg-installed_OS_is_alinux2:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-2"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-2"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·2</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·2</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Alibaba·Cloud·Linux·2.·It·is·a·rendering·of40 configuration·settings·for·Alibaba·Cloud·Linux·2.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 58534, 15 lines modifiedOffset 58534, 15 lines modified
58534 ··············<xccdf-1.2:check-content-ref·href="ssg-alinux2-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>58534 ··············<xccdf-1.2:check-content-ref·href="ssg-alinux2-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
58535 ············</xccdf-1.2:check>58535 ············</xccdf-1.2:check>
58536 ··········</xccdf-1.2:Rule>58536 ··········</xccdf-1.2:Rule>
58537 ········</xccdf-1.2:Group>58537 ········</xccdf-1.2:Group>
58538 ······</xccdf-1.2:Group>58538 ······</xccdf-1.2:Group>
58539 ····</xccdf-1.2:Benchmark>58539 ····</xccdf-1.2:Benchmark>
58540 ··</ds:component>58540 ··</ds:component>
58541 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-oval.xml"·timestamp="2025-02-28T20:08:00">58541 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-oval.xml"·timestamp="2025-03-01T22:08:00">
58542 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">58542 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
58543 ······<oval-def:generator>58543 ······<oval-def:generator>
58544 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>58544 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
58545 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>58545 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
58546 ········<oval:schema_version>5.11</oval:schema_version>58546 ········<oval:schema_version>5.11</oval:schema_version>
58547 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>58547 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
58548 ······</oval-def:generator>58548 ······</oval-def:generator>
Offset 79715, 5616 lines modifiedOffset 79715, 5616 lines modified
79715 ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/>79715 ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/>
79716 ··········</oval-def:regex_capture>79716 ··········</oval-def:regex_capture>
79717 ········</oval-def:local_variable>79717 ········</oval-def:local_variable>
79718 ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/>79718 ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/>
79719 ······</oval-def:variables>79719 ······</oval-def:variables>
79720 ····</oval-def:oval_definitions>79720 ····</oval-def:oval_definitions>
79721 ··</ds:component>79721 ··</ds:component>
79722 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-ocil.xml"·timestamp="2025-02-28T20:08:00">79722 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-ocil.xml"·timestamp="2025-03-01T22:08:00">
79723 ····<ocil:ocil>79723 ····<ocil:ocil>
79724 ······<ocil:generator>79724 ······<ocil:generator>
79725 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>79725 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
79726 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>79726 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
79727 ········<ocil:schema_version>2.0</ocil:schema_version>79727 ········<ocil:schema_version>2.0</ocil:schema_version>
79728 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>79728 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
79729 ······</ocil:generator>79729 ······</ocil:generator>
79730 ······<ocil:questionnaires>79730 ······<ocil:questionnaires>
79731 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> 
79732 ··········<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title> 
79733 ··········<ocil:actions> 
79734 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref> 
79735 ··········</ocil:actions> 
79736 ········</ocil:questionnaire> 
79737 ········<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1"> 
79738 ··········<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title> 
79739 ··········<ocil:actions> 
79740 ············<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref> 
79741 ··········</ocil:actions> 
79742 ········</ocil:questionnaire> 
79743 ········<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1"> 
79744 ··········<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title> 
79745 ··········<ocil:actions> 
79746 ············<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref> 
79747 ··········</ocil:actions> 
79748 ········</ocil:questionnaire> 
79749 ········<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">79731 ········<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">
79750 ··········<ocil:title>Verify·Owner·on·crontab</ocil:title>79732 ··········<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>
79751 ··········<ocil:actions>79733 ··········<ocil:actions>
79752 ············<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref>79734 ············<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>
79753 ··········</ocil:actions>79735 ··········</ocil:actions>
79754 ········</ocil:questionnaire>79736 ········</ocil:questionnaire>
79755 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1">79737 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1">
79756 ··········<ocil:title>Verify·User·Who·Owns·Backup·passwd·File</ocil:title>79738 ··········<ocil:title>Enable·automatic·signing·of·all·modules</ocil:title>
79757 ··········<ocil:actions>79739 ··········<ocil:actions>
79758 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>79740 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_all_action:testaction:1</ocil:test_action_ref>
79759 ··········</ocil:actions>79741 ··········</ocil:actions>
79760 ········</ocil:questionnaire>79742 ········</ocil:questionnaire>
79761 ········<ocil:questionnaire·id="ocil:ssg-account_unique_id_ocil:questionnaire:1">79743 ········<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1">
79762 ··········<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·User·IDs</ocil:title>79744 ··········<ocil:title>Ensure·logrotate·is·Installed</ocil:title>
79763 ··········<ocil:actions>79745 ··········<ocil:actions>
79764 ············<ocil:test_action_ref>ocil:ssg-account_unique_id_action:testaction:1</ocil:test_action_ref>79746 ············<ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref>
79765 ··········</ocil:actions>79747 ··········</ocil:actions>
79766 ········</ocil:questionnaire>79748 ········</ocil:questionnaire>
79767 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1"> 
79768 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>79749 ········<ocil:questionnaire·id="ocil:ssg-service_ip6tables_enabled_ocil:questionnaire:1">
 79750 ··········<ocil:title>Verify·ip6tables·Enabled·if·Using·IPv6</ocil:title>
79769 ··········<ocil:actions>79751 ··········<ocil:actions>
79770 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>79752 ············<ocil:test_action_ref>ocil:ssg-service_ip6tables_enabled_action:testaction:1</ocil:test_action_ref>
79771 ··········</ocil:actions>79753 ··········</ocil:actions>
79772 ········</ocil:questionnaire>79754 ········</ocil:questionnaire>
79773 ········<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_pub_key_ocil:questionnaire:1">79755 ········<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1">
79774 ··········<ocil:title>Verify·Group·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>79756 ··········<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title>
79775 ··········<ocil:actions>79757 ··········<ocil:actions>
79776 ············<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>79758 ············<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref>
79777 ··········</ocil:actions>79759 ··········</ocil:actions>
79778 ········</ocil:questionnaire>79760 ········</ocil:questionnaire>
79779 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_ocil:questionnaire:1">79761 ········<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1">
79780 ··········<ocil:title>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</ocil:title>79762 ··········<ocil:title>Enable·cron·Service</ocil:title>
79781 ··········<ocil:actions>79763 ··········<ocil:actions>
79782 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_tcp_syncookies_action:testaction:1</ocil:test_action_ref>79764 ············<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref>
79783 ··········</ocil:actions>79765 ··········</ocil:actions>
79784 ········</ocil:questionnaire>79766 ········</ocil:questionnaire>
79785 ········<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1">79767 ········<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1">
79786 ··········<ocil:title>Ensure·that·/etc/at.deny·does·not·exist</ocil:title>79768 ··········<ocil:title>Ensure·gpgcheck·Enabled·In·Main·yum·Configuration</ocil:title>
79787 ··········<ocil:actions>79769 ··········<ocil:actions>
79788 ············<ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>79770 ············<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>
79789 ··········</ocil:actions>79771 ··········</ocil:actions>
79790 ········</ocil:questionnaire>79772 ········</ocil:questionnaire>
79791 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1">79773 ········<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">
79792 ··········<ocil:title>Disable·Kerberos·Authentication</ocil:title>79774 ··········<ocil:title>Enable·auditd·Service</ocil:title>
79793 ··········<ocil:actions>79775 ··········<ocil:actions>
79794 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref>79776 ············<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>
79795 ··········</ocil:actions>79777 ··········</ocil:actions>
79796 ········</ocil:questionnaire>79778 ········</ocil:questionnaire>
79797 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_ocil:questionnaire:1"> 
79798 ··········<ocil:title>Configure·Response·Mode·of·ARP·Requests·for·All·IPv4·Interfaces</ocil:title>79779 ········<ocil:questionnaire·id="ocil:ssg-rpm_verify_permissions_ocil:questionnaire:1">
 79780 ··········<ocil:title>Verify·and·Correct·File·Permissions·with·RPM</ocil:title>
79799 ··········<ocil:actions>79781 ··········<ocil:actions>
Max diff block lines reached; 907063/918538 bytes (98.75%) of diff not shown.
855 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ocil.xml
855 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ocil.xml
Ordering differences only
    
Offset 3, 5607 lines modifiedOffset 3, 5607 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> 
11 ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1"> 
17 ······<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1"> 
23 ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">
29 ······<ocil:title>Verify·Owner·on·crontab</ocil:title>11 ······<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>
30 ······<ocil:actions>12 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>14 ······</ocil:actions>
33 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1">
35 ······<ocil:title>Verify·User·Who·Owns·Backup·passwd·File</ocil:title>17 ······<ocil:title>Enable·automatic·signing·of·all·modules</ocil:title>
36 ······<ocil:actions>18 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_all_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>20 ······</ocil:actions>
39 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-account_unique_id_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·User·IDs</ocil:title>23 ······<ocil:title>Ensure·logrotate·is·Installed</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-account_unique_id_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1"> 
47 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-service_ip6tables_enabled_ocil:questionnaire:1">
 29 ······<ocil:title>Verify·ip6tables·Enabled·if·Using·IPv6</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-service_ip6tables_enabled_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_pub_key_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1">
53 ······<ocil:title>Verify·Group·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>35 ······<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title>
54 ······<ocil:actions>36 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>38 ······</ocil:actions>
57 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1">
59 ······<ocil:title>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</ocil:title>41 ······<ocil:title>Enable·cron·Service</ocil:title>
60 ······<ocil:actions>42 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_tcp_syncookies_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>44 ······</ocil:actions>
63 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1"> 
65 ······<ocil:title>Ensure·that·/etc/at.deny·does·not·exist</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·gpgcheck·Enabled·In·Main·yum·Configuration</ocil:title>
66 ······<ocil:actions>48 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>50 ······</ocil:actions>
69 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">
71 ······<ocil:title>Disable·Kerberos·Authentication</ocil:title>53 ······<ocil:title>Enable·auditd·Service</ocil:title>
72 ······<ocil:actions>54 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>56 ······</ocil:actions>
75 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_ocil:questionnaire:1"> 
77 ······<ocil:title>Configure·Response·Mode·of·ARP·Requests·for·All·IPv4·Interfaces</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_permissions_ocil:questionnaire:1">
 59 ······<ocil:title>Verify·and·Correct·File·Permissions·with·RPM</ocil:title>
78 ······<ocil:actions>60 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-rpm_verify_permissions_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>62 ······</ocil:actions>
81 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-configure_ssh_crypto_policy_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-coredump_disable_storage_ocil:questionnaire:1">
83 ······<ocil:title>Configure·SSH·to·use·System·Crypto·Policy</ocil:title>65 ······<ocil:title>Disable·storing·core·dump</ocil:title>
84 ······<ocil:actions>66 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-configure_ssh_crypto_policy_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-coredump_disable_storage_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>68 ······</ocil:actions>
87 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">
89 ······<ocil:title>Verify·Group·Who·Owns·cron.hourly</ocil:title>71 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
90 ······<ocil:actions>72 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>74 ······</ocil:actions>
93 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">
95 ······<ocil:title>Set·SSH·Client·Alive·Count·Max·to·zero</ocil:title>77 ······<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title>
96 ······<ocil:actions>78 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_0_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>80 ······</ocil:actions>
99 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-ensure_logrotate_activated_ocil:questionnaire:1">
101 ······<ocil:title>Enable·Yama·support</ocil:title>83 ······<ocil:title>Ensure·Logrotate·Runs·Periodically</ocil:title>
102 ······<ocil:actions>84 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_yama_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-ensure_logrotate_activated_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>86 ······</ocil:actions>
105 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_clock_settime_ocil:questionnaire:1"> 
107 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·clock_settime</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1">
 89 ······<ocil:title>System·Audit·Logs·Must·Have·Mode·0750·or·Less·Permissive</ocil:title>
108 ······<ocil:actions>90 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_clock_settime_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>92 ······</ocil:actions>
111 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ucredit_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Uppercase·Characters</ocil:title>95 ······<ocil:title>Disable·SSH·root·Login·with·a·Password·(Insecure)</ocil:title>
114 ······<ocil:actions>96 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ucredit_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>98 ······</ocil:actions>
117 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·Rsyslog·Authenticates·Off-Loaded·Audit·Records</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1">
 101 ······<ocil:title>Disable·Kerberos·Authentication</ocil:title>
120 ······<ocil:actions>102 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>104 ······</ocil:actions>
123 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ocil:questionnaire:1"> 
Max diff block lines reached; 863595/875423 bytes (98.65%) of diff not shown.
898 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds.xml
898 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:3">28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:3">
29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·3</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·3</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml">oval:ssg-installed_OS_is_alinux3:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml">oval:ssg-installed_OS_is_alinux3:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-3"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-3"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·3</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·3</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Alibaba·Cloud·Linux·3.·It·is·a·rendering·of40 configuration·settings·for·Alibaba·Cloud·Linux·3.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 57666, 15 lines modifiedOffset 57666, 15 lines modified
57666 ··············<xccdf-1.2:check-content-ref·href="ssg-alinux3-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>57666 ··············<xccdf-1.2:check-content-ref·href="ssg-alinux3-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
57667 ············</xccdf-1.2:check>57667 ············</xccdf-1.2:check>
57668 ··········</xccdf-1.2:Rule>57668 ··········</xccdf-1.2:Rule>
57669 ········</xccdf-1.2:Group>57669 ········</xccdf-1.2:Group>
57670 ······</xccdf-1.2:Group>57670 ······</xccdf-1.2:Group>
57671 ····</xccdf-1.2:Benchmark>57671 ····</xccdf-1.2:Benchmark>
57672 ··</ds:component>57672 ··</ds:component>
57673 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-oval.xml"·timestamp="2025-02-28T20:08:00">57673 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-oval.xml"·timestamp="2025-03-01T22:08:00">
57674 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">57674 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
57675 ······<oval-def:generator>57675 ······<oval-def:generator>
57676 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>57676 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
57677 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>57677 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
57678 ········<oval:schema_version>5.11</oval:schema_version>57678 ········<oval:schema_version>5.11</oval:schema_version>
57679 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>57679 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
57680 ······</oval-def:generator>57680 ······</oval-def:generator>
Offset 77997, 5783 lines modifiedOffset 77997, 5808 lines modified
77997 ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/>77997 ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/>
77998 ··········</oval-def:regex_capture>77998 ··········</oval-def:regex_capture>
77999 ········</oval-def:local_variable>77999 ········</oval-def:local_variable>
78000 ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/>78000 ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/>
78001 ······</oval-def:variables>78001 ······</oval-def:variables>
78002 ····</oval-def:oval_definitions>78002 ····</oval-def:oval_definitions>
78003 ··</ds:component>78003 ··</ds:component>
78004 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-ocil.xml"·timestamp="2025-02-28T20:08:00">78004 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-ocil.xml"·timestamp="2025-03-01T22:08:00">
78005 ····<ocil:ocil>78005 ····<ocil:ocil>
78006 ······<ocil:generator>78006 ······<ocil:generator>
78007 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>78007 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
78008 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>78008 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
78009 ········<ocil:schema_version>2.0</ocil:schema_version>78009 ········<ocil:schema_version>2.0</ocil:schema_version>
78010 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>78010 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
78011 ······</ocil:generator>78011 ······</ocil:generator>
78012 ······<ocil:questionnaires>78012 ······<ocil:questionnaires>
78013 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_ocil:questionnaire:1"> 
78014 ··········<ocil:title>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</ocil:title> 
78015 ··········<ocil:actions> 
78016 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_tcp_syncookies_action:testaction:1</ocil:test_action_ref> 
78017 ··········</ocil:actions> 
78018 ········</ocil:questionnaire> 
78019 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">78013 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1">
78020 ··········<ocil:title>Enable·module·signature·verification</ocil:title>78014 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·creat</ocil:title>
78021 ··········<ocil:actions>78015 ··········<ocil:actions>
78022 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>78016 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref>
78023 ··········</ocil:actions>78017 ··········</ocil:actions>
78024 ········</ocil:questionnaire>78018 ········</ocil:questionnaire>
78025 ········<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">78019 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1">
78026 ··········<ocil:title>Install·the·cron·service</ocil:title>78020 ··········<ocil:title>Disable·SSH·root·Login·with·a·Password·(Insecure)</ocil:title>
78027 ··········<ocil:actions>78021 ··········<ocil:actions>
78028 ············<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>78022 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref>
78029 ··········</ocil:actions>78023 ··········</ocil:actions>
78030 ········</ocil:questionnaire>78024 ········</ocil:questionnaire>
78031 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_config_ocil:questionnaire:1">78025 ········<ocil:questionnaire·id="ocil:ssg-package_ntp_installed_ocil:questionnaire:1">
78032 ··········<ocil:title>Verify·Permissions·on·SSH·Server·config·file</ocil:title>78026 ··········<ocil:title>Install·the·ntp·service</ocil:title>
78033 ··········<ocil:actions>78027 ··········<ocil:actions>
78034 ············<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_config_action:testaction:1</ocil:test_action_ref>78028 ············<ocil:test_action_ref>ocil:ssg-package_ntp_installed_action:testaction:1</ocil:test_action_ref>
78035 ··········</ocil:actions>78029 ··········</ocil:actions>
78036 ········</ocil:questionnaire>78030 ········</ocil:questionnaire>
78037 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1"> 
78038 ··········<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>78031 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_ocil:questionnaire:1">
 78032 ··········<ocil:title>Disable·IPv6·Addressing·on·IPv6·Interfaces·by·Default</ocil:title>
78039 ··········<ocil:actions>78033 ··········<ocil:actions>
78040 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>78034 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_action:testaction:1</ocil:test_action_ref>
78041 ··········</ocil:actions>78035 ··········</ocil:actions>
78042 ········</ocil:questionnaire>78036 ········</ocil:questionnaire>
78043 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">78037 ········<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1">
78044 ··········<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>78038 ··········<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title>
78045 ··········<ocil:actions>78039 ··········<ocil:actions>
78046 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>78040 ············<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref>
78047 ··········</ocil:actions>78041 ··········</ocil:actions>
78048 ········</ocil:questionnaire>78042 ········</ocil:questionnaire>
78049 ········<ocil:questionnaire·id="ocil:ssg-postfix_network_listening_disabled_ocil:questionnaire:1"> 
78050 ··········<ocil:title>Disable·Postfix·Network·Listening</ocil:title>78043 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1">
 78044 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmod</ocil:title>
78051 ··········<ocil:actions>78045 ··········<ocil:actions>
78052 ············<ocil:test_action_ref>ocil:ssg-postfix_network_listening_disabled_action:testaction:1</ocil:test_action_ref>78046 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmod_action:testaction:1</ocil:test_action_ref>
78053 ··········</ocil:actions>78047 ··········</ocil:actions>
78054 ········</ocil:questionnaire>78048 ········</ocil:questionnaire>
78055 ········<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1"> 
78056 ··········<ocil:title>Remove·NIS·Client</ocil:title>78049 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">
 78050 ··········<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>
78057 ··········<ocil:actions>78051 ··········<ocil:actions>
78058 ············<ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref>78052 ············<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>
78059 ··········</ocil:actions>78053 ··········</ocil:actions>
78060 ········</ocil:questionnaire>78054 ········</ocil:questionnaire>
78061 ········<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1"> 
78062 ··········<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>78055 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">
 78056 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>
78063 ··········<ocil:actions>78057 ··········<ocil:actions>
78064 ············<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>78058 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>
78065 ··········</ocil:actions>78059 ··········</ocil:actions>
78066 ········</ocil:questionnaire>78060 ········</ocil:questionnaire>
78067 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1">78061 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_group_ocil:questionnaire:1">
78068 ··········<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title>78062 ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/group</ocil:title>
78069 ··········<ocil:actions>78063 ··········<ocil:actions>
78070 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>78064 ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_group_action:testaction:1</ocil:test_action_ref>
78071 ··········</ocil:actions>78065 ··········</ocil:actions>
78072 ········</ocil:questionnaire>78066 ········</ocil:questionnaire>
78073 ········<ocil:questionnaire·id="ocil:ssg-package_sudo_installed_ocil:questionnaire:1"> 
78074 ··········<ocil:title>Install·sudo·Package</ocil:title>78067 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1">
 78068 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lsetxattr</ocil:title>
78075 ··········<ocil:actions>78069 ··········<ocil:actions>
78076 ············<ocil:test_action_ref>ocil:ssg-package_sudo_installed_action:testaction:1</ocil:test_action_ref>78070 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>
78077 ··········</ocil:actions>78071 ··········</ocil:actions>
78078 ········</ocil:questionnaire>78072 ········</ocil:questionnaire>
Max diff block lines reached; 907121/919294 bytes (98.68%) of diff not shown.
856 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ocil.xml
856 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ocil.xml
Ordering differences only
    
Offset 3, 5774 lines modifiedOffset 3, 5799 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_ocil:questionnaire:1"> 
11 ······<ocil:title>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_tcp_syncookies_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1">
17 ······<ocil:title>Enable·module·signature·verification</ocil:title>11 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·creat</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1"> 
23 ······<ocil:title>Install·the·cron·service</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1">
 17 ······<ocil:title>Disable·SSH·root·Login·with·a·Password·(Insecure)</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_config_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-package_ntp_installed_ocil:questionnaire:1">
29 ······<ocil:title>Verify·Permissions·on·SSH·Server·config·file</ocil:title>23 ······<ocil:title>Install·the·ntp·service</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_config_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-package_ntp_installed_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1"> 
35 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_ocil:questionnaire:1">
 29 ······<ocil:title>Disable·IPv6·Addressing·on·IPv6·Interfaces·by·Default</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1">
41 ······<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>35 ······<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-postfix_network_listening_disabled_ocil:questionnaire:1"> 
47 ······<ocil:title>Disable·Postfix·Network·Listening</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1">
 41 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmod</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-postfix_network_listening_disabled_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmod_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1"> 
53 ······<ocil:title>Remove·NIS·Client</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1"> 
59 ······<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">
 53 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_group_ocil:questionnaire:1">
65 ······<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title>59 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/group</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_group_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-package_sudo_installed_ocil:questionnaire:1"> 
71 ······<ocil:title>Install·sudo·Package</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1">
 65 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lsetxattr</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-package_sudo_installed_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_ocil:questionnaire:1"> 
77 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·truncate</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_permissions_ocil:questionnaire:1">
 71 ······<ocil:title>Ensure·System·Log·Files·Have·Correct·Permissions</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_permissions_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_home_dirs_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·that·User·Home·Directories·are·not·Group-Writable·or·World-Readable</ocil:title>77 ······<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_home_dirs_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-gid_passwd_group_same_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">
89 ······<ocil:title>All·GIDs·referenced·in·/etc/passwd·must·be·defined·in·/etc/group</ocil:title>83 ······<ocil:title>Install·the·cron·service</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-gid_passwd_group_same_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1"> 
95 ······<ocil:title>Specify·module·signing·key·to·use</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1">
 89 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·openat</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-service_qpidd_disabled_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-service_qpidd_disabled_ocil:questionnaire:1">
101 ······<ocil:title>Disable·Apache·Qpid·(qpidd)</ocil:title>95 ······<ocil:title>Disable·Apache·Qpid·(qpidd)</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-service_qpidd_disabled_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-service_qpidd_disabled_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sshd_allow_only_protocol2_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_permissions_ocil:questionnaire:1">
107 ······<ocil:title>Allow·Only·SSH·Protocol·2</ocil:title>101 ······<ocil:title>Verify·and·Correct·File·Permissions·with·RPM</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sshd_allow_only_protocol2_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-rpm_verify_permissions_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-chronyd_run_as_chrony_user_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title>107 ······<ocil:title>Ensure·that·chronyd·is·running·under·chrony·user·account</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-chronyd_run_as_chrony_user_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_hourly_ocil:questionnaire:1"> 
119 ······<ocil:title>Verify·Permissions·on·cron.hourly</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1">
 113 ······<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
Max diff block lines reached; 864787/876809 bytes (98.63%) of diff not shown.
1.02 MB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ds.xml
1.02 MB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-org.almalinux.alsa-9.xml.bz2"·xlink:href="https://security.almalinux.org/oval/org.almalinux.alsa-9.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-org.almalinux.alsa-9.xml.bz2"·xlink:href="https://security.almalinux.org/oval/org.almalinux.alsa-9.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:almalinux:almalinux:9">30 ······<cpe-dict:cpe-item·name="cpe:/o:almalinux:almalinux:9">
31 ········<cpe-dict:title·xml:lang="en-us">AlmaLinux·OS·9</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">AlmaLinux·OS·9</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml">oval:ssg-installed_OS_is_almalinux9:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml">oval:ssg-installed_OS_is_almalinux9:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALMALINUX-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALMALINUX-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·AlmaLinux·OS·9</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·AlmaLinux·OS·9</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·AlmaLinux·OS·9.·It·is·a·rendering·of42 configuration·settings·for·AlmaLinux·OS·9.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 131587, 15 lines modifiedOffset 131587, 15 lines modified
131587 ··············<xccdf-1.2:check-content-ref·href="ssg-almalinux9-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/>131587 ··············<xccdf-1.2:check-content-ref·href="ssg-almalinux9-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/>
131588 ············</xccdf-1.2:check>131588 ············</xccdf-1.2:check>
131589 ··········</xccdf-1.2:Rule>131589 ··········</xccdf-1.2:Rule>
131590 ········</xccdf-1.2:Group>131590 ········</xccdf-1.2:Group>
131591 ······</xccdf-1.2:Group>131591 ······</xccdf-1.2:Group>
131592 ····</xccdf-1.2:Benchmark>131592 ····</xccdf-1.2:Benchmark>
131593 ··</ds:component>131593 ··</ds:component>
131594 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-oval.xml"·timestamp="2025-02-28T20:08:00">131594 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-oval.xml"·timestamp="2025-03-01T22:08:00">
131595 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">131595 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
131596 ······<oval-def:generator>131596 ······<oval-def:generator>
131597 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>131597 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
131598 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>131598 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
131599 ········<oval:schema_version>5.11</oval:schema_version>131599 ········<oval:schema_version>5.11</oval:schema_version>
131600 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>131600 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
131601 ······</oval-def:generator>131601 ······</oval-def:generator>
Offset 154336, 6814 lines modifiedOffset 154336, 6658 lines modified
154336 ············</oval-def:arithmetic>154336 ············</oval-def:arithmetic>
154337 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>154337 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
154338 ··········</oval-def:arithmetic>154338 ··········</oval-def:arithmetic>
154339 ········</oval-def:local_variable>154339 ········</oval-def:local_variable>
154340 ······</oval-def:variables>154340 ······</oval-def:variables>
154341 ····</oval-def:oval_definitions>154341 ····</oval-def:oval_definitions>
154342 ··</ds:component>154342 ··</ds:component>
154343 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"·timestamp="2025-02-28T20:08:00">154343 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"·timestamp="2025-03-01T22:08:00">
154344 ····<ocil:ocil>154344 ····<ocil:ocil>
154345 ······<ocil:generator>154345 ······<ocil:generator>
154346 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>154346 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
154347 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>154347 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
154348 ········<ocil:schema_version>2.0</ocil:schema_version>154348 ········<ocil:schema_version>2.0</ocil:schema_version>
154349 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>154349 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
154350 ······</ocil:generator>154350 ······</ocil:generator>
154351 ······<ocil:questionnaires>154351 ······<ocil:questionnaires>
154352 ········<ocil:questionnaire·id="ocil:ssg-package_aide_installed_ocil:questionnaire:1">154352 ········<ocil:questionnaire·id="ocil:ssg-mount_option_home_nodev_ocil:questionnaire:1">
 154353 ··········<ocil:title>Add·nodev·Option·to·/home</ocil:title>
154353 ··········<ocil:title>Install·AIDE</ocil:title> 
154354 ··········<ocil:actions> 
154355 ············<ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref> 
154356 ··········</ocil:actions> 
154357 ········</ocil:questionnaire> 
154358 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_passwd_ocil:questionnaire:1"> 
154359 ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/passwd</ocil:title> 
154360 ··········<ocil:actions>154354 ··········<ocil:actions>
154361 ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_passwd_action:testaction:1</ocil:test_action_ref>154355 ············<ocil:test_action_ref>ocil:ssg-mount_option_home_nodev_action:testaction:1</ocil:test_action_ref>
154362 ··········</ocil:actions>154356 ··········</ocil:actions>
154363 ········</ocil:questionnaire>154357 ········</ocil:questionnaire>
154364 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dictcheck_ocil:questionnaire:1">154358 ········<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_etc_shadow_ocil:questionnaire:1">
154365 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Prevent·the·Use·of·Dictionary·Words</ocil:title>154359 ··········<ocil:title>Ensure·There·Are·No·Accounts·With·Blank·or·Null·Passwords</ocil:title>
154366 ··········<ocil:actions>154360 ··········<ocil:actions>
154367 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dictcheck_action:testaction:1</ocil:test_action_ref>154361 ············<ocil:test_action_ref>ocil:ssg-no_empty_passwords_etc_shadow_action:testaction:1</ocil:test_action_ref>
154368 ··········</ocil:actions>154362 ··········</ocil:actions>
154369 ········</ocil:questionnaire>154363 ········</ocil:questionnaire>
154370 ········<ocil:questionnaire·id="ocil:ssg-xwindows_runlevel_target_ocil:questionnaire:1"> 
154371 ··········<ocil:title>Disable·Graphical·Environment·Startup·By·Setting·Default·Target</ocil:title>154364 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1">
 154365 ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>
154372 ··········<ocil:actions>154366 ··········<ocil:actions>
154373 ············<ocil:test_action_ref>ocil:ssg-xwindows_runlevel_target_action:testaction:1</ocil:test_action_ref>154367 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>
154374 ··········</ocil:actions>154368 ··········</ocil:actions>
154375 ········</ocil:questionnaire>154369 ········</ocil:questionnaire>
154376 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1">154370 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1">
154377 ··········<ocil:title>Verify·Permissions·on·group·File</ocil:title>154371 ··········<ocil:title>Enable·PAM</ocil:title>
154378 ··········<ocil:actions>154372 ··········<ocil:actions>
154379 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_group_action:testaction:1</ocil:test_action_ref>154373 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_pam_action:testaction:1</ocil:test_action_ref>
154380 ··········</ocil:actions>154374 ··········</ocil:actions>
154381 ········</ocil:questionnaire>154375 ········</ocil:questionnaire>
154382 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_sctp_disabled_ocil:questionnaire:1">154376 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shells_ocil:questionnaire:1">
154383 ··········<ocil:title>Disable·SCTP·Support</ocil:title>154377 ··········<ocil:title>Verify·Permissions·on·/etc/shells·File</ocil:title>
154384 ··········<ocil:actions>154378 ··········<ocil:actions>
154385 ············<ocil:test_action_ref>ocil:ssg-kernel_module_sctp_disabled_action:testaction:1</ocil:test_action_ref>154379 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shells_action:testaction:1</ocil:test_action_ref>
154386 ··········</ocil:actions>154380 ··········</ocil:actions>
154387 ········</ocil:questionnaire>154381 ········</ocil:questionnaire>
154388 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1"> 
154389 ··········<ocil:title>Verify·Permissions·on·crontab</ocil:title>154382 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1">
 154383 ··········<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>
154390 ··········<ocil:actions>154384 ··········<ocil:actions>
154391 ············<ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref>154385 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>
154392 ··········</ocil:actions>154386 ··········</ocil:actions>
154393 ········</ocil:questionnaire>154387 ········</ocil:questionnaire>
154394 ········<ocil:questionnaire·id="ocil:ssg-package_audispd-plugins_installed_ocil:questionnaire:1">154388 ········<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1">
154395 ··········<ocil:title>Install·audispd-plugins·Package</ocil:title>154389 ··········<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title>
154396 ··········<ocil:actions>154390 ··········<ocil:actions>
154397 ············<ocil:test_action_ref>ocil:ssg-package_audispd-plugins_installed_action:testaction:1</ocil:test_action_ref>154391 ············<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref>
154398 ··········</ocil:actions>154392 ··········</ocil:actions>
154399 ········</ocil:questionnaire>154393 ········</ocil:questionnaire>
154400 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1"> 
154401 ··········<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>154394 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_shadow_ocil:questionnaire:1">
 154395 ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/shadow</ocil:title>
154402 ··········<ocil:actions>154396 ··········<ocil:actions>
154403 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>154397 ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_shadow_action:testaction:1</ocil:test_action_ref>
154404 ··········</ocil:actions>154398 ··········</ocil:actions>
154405 ········</ocil:questionnaire>154399 ········</ocil:questionnaire>
154406 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">154400 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_userhelper_ocil:questionnaire:1">
154407 ··········<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>154401 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·userhelper</ocil:title>
154408 ··········<ocil:actions>154402 ··········<ocil:actions>
154409 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>154403 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_userhelper_action:testaction:1</ocil:test_action_ref>
154410 ··········</ocil:actions>154404 ··········</ocil:actions>
154411 ········</ocil:questionnaire>154405 ········</ocil:questionnaire>
154412 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1">154406 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1">
154413 ··········<ocil:title>Verify·Permissions·on·shadow·File</ocil:title>154407 ··········<ocil:title>Record·Any·Attempts·to·Run·chcon</ocil:title>
154414 ··········<ocil:actions>154408 ··········<ocil:actions>
154415 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shadow_action:testaction:1</ocil:test_action_ref>154409 ············<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref>
154416 ··········</ocil:actions>154410 ··········</ocil:actions>
154417 ········</ocil:questionnaire>154411 ········</ocil:questionnaire>
154418 ········<ocil:questionnaire·id="ocil:ssg-package_rsync_removed_ocil:questionnaire:1">154412 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_daily_ocil:questionnaire:1">
Max diff block lines reached; 1058266/1070228 bytes (98.88%) of diff not shown.
998 KB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ocil.xml
998 KB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ocil.xml
Ordering differences only
    
Offset 3, 6805 lines modifiedOffset 3, 6649 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-package_aide_installed_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nodev_ocil:questionnaire:1">
 11 ······<ocil:title>Add·nodev·Option·to·/home</ocil:title>
11 ······<ocil:title>Install·AIDE</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_passwd_ocil:questionnaire:1"> 
17 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/passwd</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_passwd_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nodev_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dictcheck_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_etc_shadow_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Prevent·the·Use·of·Dictionary·Words</ocil:title>17 ······<ocil:title>Ensure·There·Are·No·Accounts·With·Blank·or·Null·Passwords</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dictcheck_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-no_empty_passwords_etc_shadow_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-xwindows_runlevel_target_ocil:questionnaire:1"> 
29 ······<ocil:title>Disable·Graphical·Environment·Startup·By·Setting·Default·Target</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1">
 23 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-xwindows_runlevel_target_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Permissions·on·group·File</ocil:title>29 ······<ocil:title>Enable·PAM</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_group_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_pam_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_sctp_disabled_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shells_ocil:questionnaire:1">
41 ······<ocil:title>Disable·SCTP·Support</ocil:title>35 ······<ocil:title>Verify·Permissions·on·/etc/shells·File</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kernel_module_sctp_disabled_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shells_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1"> 
47 ······<ocil:title>Verify·Permissions·on·crontab</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1">
 41 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-package_audispd-plugins_installed_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1">
53 ······<ocil:title>Install·audispd-plugins·Package</ocil:title>47 ······<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-package_audispd-plugins_installed_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1"> 
59 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_shadow_ocil:questionnaire:1">
 53 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/shadow</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_shadow_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_userhelper_ocil:questionnaire:1">
65 ······<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>59 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·userhelper</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_userhelper_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Permissions·on·shadow·File</ocil:title>65 ······<ocil:title>Record·Any·Attempts·to·Run·chcon</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shadow_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-package_rsync_removed_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_daily_ocil:questionnaire:1">
77 ······<ocil:title>Uninstall·rsync·Package</ocil:title>71 ······<ocil:title>Verify·Permissions·on·cron.daily</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-package_rsync_removed_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_daily_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-enable_authselect_ocil:questionnaire:1"> 
83 ······<ocil:title>Enable·authselect</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-firewalld_loopback_traffic_trusted_ocil:questionnaire:1">
 77 ······<ocil:title>Configure·Firewalld·to·Trust·Loopback·Traffic</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-enable_authselect_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-firewalld_loopback_traffic_trusted_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1"> 
89 ······<ocil:title>System·Audit·Logs·Must·Have·Mode·0750·or·Less·Permissive</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-service_rsyncd_disabled_ocil:questionnaire:1">
 83 ······<ocil:title>Ensure·rsyncd·service·is·disabled</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-service_rsyncd_disabled_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_pam_pwquality_installed_ocil:questionnaire:1"> 
95 ······<ocil:title>Install·pam_pwquality·Package</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
 89 ······<ocil:title>Disable·X11·Forwarding</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_pam_pwquality_installed_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_ownership_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1">
101 ······<ocil:title>Verify·and·Correct·Ownership·with·RPM</ocil:title>95 ······<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-rpm_verify_ownership_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_private_key_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dictcheck_ocil:questionnaire:1">
107 ······<ocil:title>Verify·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>101 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Prevent·the·Use·of·Dictionary·Words</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dictcheck_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_cramfs_disabled_ocil:questionnaire:1"> 
113 ······<ocil:title>Disable·Mounting·of·cramfs</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_usr_share_ocil:questionnaire:1">
 107 ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls·in·usr/share</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_module_cramfs_disabled_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_usr_share_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_passwordauth_ocil:questionnaire:1"> 
119 ······<ocil:title>Set·PAM''s·Password·Hashing·Algorithm·-·password-auth</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-configure_ssh_crypto_policy_ocil:questionnaire:1">
 113 ······<ocil:title>Configure·SSH·to·use·System·Crypto·Policy</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
Max diff block lines reached; 1009560/1021639 bytes (98.82%) of diff not shown.
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ds.xml
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:23">28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:23">
29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·23</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·23</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml">oval:ssg-installed_OS_is_anolis23:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml">oval:ssg-installed_OS_is_anolis23:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-23"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-23"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·23</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·23</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Anolis·OS·23.·It·is·a·rendering·of40 configuration·settings·for·Anolis·OS·23.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 66305, 15 lines modifiedOffset 66305, 15 lines modified
66305 ··············<xccdf-1.2:check-content-ref·href="ssg-anolis23-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>66305 ··············<xccdf-1.2:check-content-ref·href="ssg-anolis23-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
66306 ············</xccdf-1.2:check>66306 ············</xccdf-1.2:check>
66307 ··········</xccdf-1.2:Rule>66307 ··········</xccdf-1.2:Rule>
66308 ········</xccdf-1.2:Group>66308 ········</xccdf-1.2:Group>
66309 ······</xccdf-1.2:Group>66309 ······</xccdf-1.2:Group>
66310 ····</xccdf-1.2:Benchmark>66310 ····</xccdf-1.2:Benchmark>
66311 ··</ds:component>66311 ··</ds:component>
66312 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-oval.xml"·timestamp="2025-02-28T20:08:00">66312 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-oval.xml"·timestamp="2025-03-01T22:08:00">
66313 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">66313 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
66314 ······<oval-def:generator>66314 ······<oval-def:generator>
66315 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>66315 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
66316 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>66316 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
66317 ········<oval:schema_version>5.11</oval:schema_version>66317 ········<oval:schema_version>5.11</oval:schema_version>
66318 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>66318 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
66319 ······</oval-def:generator>66319 ······</oval-def:generator>
Offset 90165, 7611 lines modifiedOffset 90165, 7701 lines modified
90165 ············</oval-def:arithmetic>90165 ············</oval-def:arithmetic>
90166 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>90166 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
90167 ··········</oval-def:arithmetic>90167 ··········</oval-def:arithmetic>
90168 ········</oval-def:local_variable>90168 ········</oval-def:local_variable>
90169 ······</oval-def:variables>90169 ······</oval-def:variables>
90170 ····</oval-def:oval_definitions>90170 ····</oval-def:oval_definitions>
90171 ··</ds:component>90171 ··</ds:component>
90172 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-ocil.xml"·timestamp="2025-02-28T20:08:00">90172 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-ocil.xml"·timestamp="2025-03-01T22:08:00">
90173 ····<ocil:ocil>90173 ····<ocil:ocil>
90174 ······<ocil:generator>90174 ······<ocil:generator>
90175 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>90175 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
90176 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>90176 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
90177 ········<ocil:schema_version>2.0</ocil:schema_version>90177 ········<ocil:schema_version>2.0</ocil:schema_version>
90178 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>90178 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
90179 ······</ocil:generator>90179 ······</ocil:generator>
90180 ······<ocil:questionnaires>90180 ······<ocil:questionnaires>
90181 ········<ocil:questionnaire·id="ocil:ssg-service_dovecot_disabled_ocil:questionnaire:1">90181 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">
90182 ··········<ocil:title>Disable·Dovecot·Service</ocil:title>90182 ··········<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>
90183 ··········<ocil:actions>90183 ··········<ocil:actions>
90184 ············<ocil:test_action_ref>ocil:ssg-service_dovecot_disabled_action:testaction:1</ocil:test_action_ref>90184 ············<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>
90185 ··········</ocil:actions>90185 ··········</ocil:actions>
90186 ········</ocil:questionnaire>90186 ········</ocil:questionnaire>
90187 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1"> 
90188 ··········<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>90187 ········<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1">
 90188 ··········<ocil:title>Ensure·gpgcheck·Enabled·In·Main·yum·Configuration</ocil:title>
90189 ··········<ocil:actions>90189 ··········<ocil:actions>
90190 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>90190 ············<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>
90191 ··········</ocil:actions>90191 ··········</ocil:actions>
90192 ········</ocil:questionnaire>90192 ········</ocil:questionnaire>
90193 ········<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">90193 ········<ocil:questionnaire·id="ocil:ssg-package_postfix_installed_ocil:questionnaire:1">
90194 ··········<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>90194 ··········<ocil:title>The·Postfix·package·is·installed</ocil:title>
90195 ··········<ocil:actions>90195 ··········<ocil:actions>
90196 ············<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>90196 ············<ocil:test_action_ref>ocil:ssg-package_postfix_installed_action:testaction:1</ocil:test_action_ref>
90197 ··········</ocil:actions>90197 ··········</ocil:actions>
90198 ········</ocil:questionnaire>90198 ········</ocil:questionnaire>
90199 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">90199 ········<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1">
90200 ··········<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>90200 ··········<ocil:title>Modify·the·System·Login·Banner</ocil:title>
90201 ··········<ocil:actions>90201 ··········<ocil:actions>
90202 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>90202 ············<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref>
90203 ··········</ocil:actions>90203 ··········</ocil:actions>
90204 ········</ocil:questionnaire>90204 ········</ocil:questionnaire>
90205 ········<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">90205 ········<ocil:questionnaire·id="ocil:ssg-service_rsyncd_disabled_ocil:questionnaire:1">
90206 ··········<ocil:title>Verify·Owner·on·crontab</ocil:title>90206 ··········<ocil:title>Ensure·rsyncd·service·is·disabled</ocil:title>
90207 ··········<ocil:actions>90207 ··········<ocil:actions>
90208 ············<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref>90208 ············<ocil:test_action_ref>ocil:ssg-service_rsyncd_disabled_action:testaction:1</ocil:test_action_ref>
90209 ··········</ocil:actions>90209 ··········</ocil:actions>
90210 ········</ocil:questionnaire>90210 ········</ocil:questionnaire>
90211 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_hibernation_ocil:questionnaire:1">90211 ········<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
90212 ··········<ocil:title>Disable·hibernation</ocil:title>90212 ··········<ocil:title>Enable·systemd-journald·Service</ocil:title>
90213 ··········<ocil:actions>90213 ··········<ocil:actions>
90214 ············<ocil:test_action_ref>ocil:ssg-kernel_config_hibernation_action:testaction:1</ocil:test_action_ref>90214 ············<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
90215 ··········</ocil:actions>90215 ··········</ocil:actions>
90216 ········</ocil:questionnaire>90216 ········</ocil:questionnaire>
90217 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_weekly_ocil:questionnaire:1">90217 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1">
90218 ··········<ocil:title>Verify·Group·Who·Owns·cron.weekly</ocil:title>90218 ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>
90219 ··········<ocil:actions>90219 ··········<ocil:actions>
90220 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_weekly_action:testaction:1</ocil:test_action_ref>90220 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>
90221 ··········</ocil:actions>90221 ··········</ocil:actions>
90222 ········</ocil:questionnaire>90222 ········</ocil:questionnaire>
90223 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_security_writable_hooks_ocil:questionnaire:1"> 
90224 ··········<ocil:title>Disable·mutable·hooks</ocil:title>90223 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1">
 90224 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title>
90225 ··········<ocil:actions>90225 ··········<ocil:actions>
90226 ············<ocil:test_action_ref>ocil:ssg-kernel_config_security_writable_hooks_action:testaction:1</ocil:test_action_ref>90226 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>
90227 ··········</ocil:actions>90227 ··········</ocil:actions>
90228 ········</ocil:questionnaire>90228 ········</ocil:questionnaire>
90229 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1">90229 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1">
90230 ··········<ocil:title>Verify·Permissions·on·/etc/cron.allow·file</ocil:title>90230 ··········<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title>
90231 ··········<ocil:actions>90231 ··········<ocil:actions>
90232 ············<ocil:test_action_ref>ocil:ssg-file_permissions_cron_allow_action:testaction:1</ocil:test_action_ref>90232 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>
90233 ··········</ocil:actions>90233 ··········</ocil:actions>
90234 ········</ocil:questionnaire>90234 ········</ocil:questionnaire>
90235 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_sha512_ocil:questionnaire:1"> 
90236 ··········<ocil:title>Sign·kernel·modules·with·SHA-512</ocil:title>90235 ········<ocil:questionnaire·id="ocil:ssg-file_groupownership_home_directories_ocil:questionnaire:1">
 90236 ··········<ocil:title>All·Interactive·User·Home·Directories·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>
90237 ··········<ocil:actions>90237 ··········<ocil:actions>
90238 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_sha512_action:testaction:1</ocil:test_action_ref>90238 ············<ocil:test_action_ref>ocil:ssg-file_groupownership_home_directories_action:testaction:1</ocil:test_action_ref>
90239 ··········</ocil:actions>90239 ··········</ocil:actions>
90240 ········</ocil:questionnaire>90240 ········</ocil:questionnaire>
90241 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1">90241 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount2_ocil:questionnaire:1">
90242 ··········<ocil:title>Specify·module·signing·key·to·use</ocil:title>90242 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount2</ocil:title>
90243 ··········<ocil:actions>90243 ··········<ocil:actions>
90244 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>90244 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount2_action:testaction:1</ocil:test_action_ref>
90245 ··········</ocil:actions>90245 ··········</ocil:actions>
90246 ········</ocil:questionnaire>90246 ········</ocil:questionnaire>
90247 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">90247 ········<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">
90248 ··········<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>90248 ··········<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>
Max diff block lines reached; 1042952/1055046 bytes (98.85%) of diff not shown.
984 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ocil.xml
984 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ocil.xml
Ordering differences only
    
Offset 3, 7602 lines modifiedOffset 3, 7692 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-service_dovecot_disabled_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">
11 ······<ocil:title>Disable·Dovecot·Service</ocil:title>11 ······<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-service_dovecot_disabled_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1"> 
17 ······<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1">
 17 ······<ocil:title>Ensure·gpgcheck·Enabled·In·Main·yum·Configuration</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-package_postfix_installed_ocil:questionnaire:1">
23 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>23 ······<ocil:title>The·Postfix·package·is·installed</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-package_postfix_installed_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1">
29 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>29 ······<ocil:title>Modify·the·System·Login·Banner</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-service_rsyncd_disabled_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Owner·on·crontab</ocil:title>35 ······<ocil:title>Ensure·rsyncd·service·is·disabled</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-service_rsyncd_disabled_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_hibernation_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
41 ······<ocil:title>Disable·hibernation</ocil:title>41 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_hibernation_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_weekly_ocil:questionnaire:1"> 
47 ······<ocil:title>Verify·Group·Who·Owns·cron.weekly</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1">
 47 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_weekly_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_writable_hooks_ocil:questionnaire:1"> 
53 ······<ocil:title>Disable·mutable·hooks</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1">
 53 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_writable_hooks_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1"> 
59 ······<ocil:title>Verify·Permissions·on·/etc/cron.allow·file</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1">
 59 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_allow_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_sha512_ocil:questionnaire:1"> 
65 ······<ocil:title>Sign·kernel·modules·with·SHA-512</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_home_directories_ocil:questionnaire:1">
 65 ······<ocil:title>All·Interactive·User·Home·Directories·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_sha512_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_home_directories_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1"> 
71 ······<ocil:title>Specify·module·signing·key·to·use</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount2_ocil:questionnaire:1">
 71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount2</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount2_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">
77 ······<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>77 ······<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_shutdown_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·shutdown</ocil:title>83 ······<ocil:title>Verify·Permissions·on·crontab</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_shutdown_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1"> 
89 ······<ocil:title>System·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_ocil:questionnaire:1">
 89 ······<ocil:title>Configure·System·to·Forward·All·Mail·From·Postmaster·to·The·Root·Account</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_postmaster_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_grub2_cfg_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">
95 ······<ocil:title>Verify·/boot/grub2/grub.cfg·Group·Ownership</ocil:title>95 ······<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_grub2_cfg_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_issue_ocil:questionnaire:1"> 
101 ······<ocil:title>Verify·permissions·on·System·Login·Banner</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1">
 101 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_library_dirs_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_delete_ocil:questionnaire:1">
107 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Ownership</ocil:title>107 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Unloading·-·delete_module</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_delete_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1">
113 ······<ocil:title>IOMMU·configuration·directive</ocil:title>113 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-grub2_enable_iommu_force_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">
119 ······<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>119 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 994547/1007102 bytes (98.75%) of diff not shown.
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds.xml
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:8">28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:8">
29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·8</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·8</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml">oval:ssg-installed_OS_is_anolis8:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml">oval:ssg-installed_OS_is_anolis8:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·8</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·8</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Anolis·OS·8.·It·is·a·rendering·of40 configuration·settings·for·Anolis·OS·8.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 66305, 15 lines modifiedOffset 66305, 15 lines modified
66305 ··············<xccdf-1.2:check-content-ref·href="ssg-anolis8-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>66305 ··············<xccdf-1.2:check-content-ref·href="ssg-anolis8-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
66306 ············</xccdf-1.2:check>66306 ············</xccdf-1.2:check>
66307 ··········</xccdf-1.2:Rule>66307 ··········</xccdf-1.2:Rule>
66308 ········</xccdf-1.2:Group>66308 ········</xccdf-1.2:Group>
66309 ······</xccdf-1.2:Group>66309 ······</xccdf-1.2:Group>
66310 ····</xccdf-1.2:Benchmark>66310 ····</xccdf-1.2:Benchmark>
66311 ··</ds:component>66311 ··</ds:component>
66312 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-oval.xml"·timestamp="2025-02-28T20:08:00">66312 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-oval.xml"·timestamp="2025-03-01T22:08:00">
66313 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">66313 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
66314 ······<oval-def:generator>66314 ······<oval-def:generator>
66315 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>66315 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
66316 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>66316 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
66317 ········<oval:schema_version>5.11</oval:schema_version>66317 ········<oval:schema_version>5.11</oval:schema_version>
66318 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>66318 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
66319 ······</oval-def:generator>66319 ······</oval-def:generator>
Offset 90165, 6620 lines modifiedOffset 90165, 6614 lines modified
90165 ············</oval-def:arithmetic>90165 ············</oval-def:arithmetic>
90166 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>90166 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
90167 ··········</oval-def:arithmetic>90167 ··········</oval-def:arithmetic>
90168 ········</oval-def:local_variable>90168 ········</oval-def:local_variable>
90169 ······</oval-def:variables>90169 ······</oval-def:variables>
90170 ····</oval-def:oval_definitions>90170 ····</oval-def:oval_definitions>
90171 ··</ds:component>90171 ··</ds:component>
90172 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-ocil.xml"·timestamp="2025-02-28T20:08:00">90172 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-ocil.xml"·timestamp="2025-03-01T22:08:00">
90173 ····<ocil:ocil>90173 ····<ocil:ocil>
90174 ······<ocil:generator>90174 ······<ocil:generator>
90175 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>90175 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
90176 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>90176 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
90177 ········<ocil:schema_version>2.0</ocil:schema_version>90177 ········<ocil:schema_version>2.0</ocil:schema_version>
90178 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>90178 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
90179 ······</ocil:generator>90179 ······</ocil:generator>
90180 ······<ocil:questionnaires>90180 ······<ocil:questionnaires>
90181 ········<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1"> 
90182 ··········<ocil:title>Modify·the·System·Login·Banner</ocil:title> 
90183 ··········<ocil:actions> 
90184 ············<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref> 
90185 ··········</ocil:actions> 
90186 ········</ocil:questionnaire> 
90187 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1"> 
90188 ··········<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title> 
90189 ··········<ocil:actions> 
90190 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref> 
90191 ··········</ocil:actions> 
90192 ········</ocil:questionnaire> 
90193 ········<ocil:questionnaire·id="ocil:ssg-sudo_require_authentication_ocil:questionnaire:1">90181 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">
90194 ··········<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo</ocil:title>90182 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>
90195 ··········<ocil:actions>90183 ··········<ocil:actions>
90196 ············<ocil:test_action_ref>ocil:ssg-sudo_require_authentication_action:testaction:1</ocil:test_action_ref>90184 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>
90197 ··········</ocil:actions>90185 ··········</ocil:actions>
90198 ········</ocil:questionnaire>90186 ········</ocil:questionnaire>
90199 ········<ocil:questionnaire·id="ocil:ssg-package_MFEhiplsm_installed_ocil:questionnaire:1">90187 ········<ocil:questionnaire·id="ocil:ssg-account_unique_name_ocil:questionnaire:1">
90200 ··········<ocil:title>Install·the·Host·Intrusion·Prevention·System·(HIPS)·Module</ocil:title>90188 ··········<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·Names</ocil:title>
90201 ··········<ocil:actions>90189 ··········<ocil:actions>
90202 ············<ocil:test_action_ref>ocil:ssg-package_MFEhiplsm_installed_action:testaction:1</ocil:test_action_ref>90190 ············<ocil:test_action_ref>ocil:ssg-account_unique_name_action:testaction:1</ocil:test_action_ref>
90203 ··········</ocil:actions>90191 ··········</ocil:actions>
90204 ········</ocil:questionnaire>90192 ········</ocil:questionnaire>
90205 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1"> 
90206 ··········<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv4·Interfaces</ocil:title>90193 ········<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1">
 90194 ··········<ocil:title>Set·Password·Minimum·Age</ocil:title>
90207 ··········<ocil:actions>90195 ··········<ocil:actions>
90208 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>90196 ············<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref>
90209 ··········</ocil:actions>90197 ··········</ocil:actions>
90210 ········</ocil:questionnaire>90198 ········</ocil:questionnaire>
90211 ········<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">90199 ········<ocil:questionnaire·id="ocil:ssg-chronyd_server_directive_ocil:questionnaire:1">
90212 ··········<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>90200 ··········<ocil:title>Ensure·Chrony·is·only·configured·with·the·server·directive</ocil:title>
90213 ··········<ocil:actions>90201 ··········<ocil:actions>
90214 ············<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>90202 ············<ocil:test_action_ref>ocil:ssg-chronyd_server_directive_action:testaction:1</ocil:test_action_ref>
90215 ··········</ocil:actions>90203 ··········</ocil:actions>
90216 ········</ocil:questionnaire>90204 ········</ocil:questionnaire>
90217 ········<ocil:questionnaire·id="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1">90205 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1">
90218 ··········<ocil:title>Configure·BIND·to·use·System·Crypto·Policy</ocil:title>90206 ··········<ocil:title>Set·Password·Warning·Age</ocil:title>
90219 ··········<ocil:actions>90207 ··········<ocil:actions>
90220 ············<ocil:test_action_ref>ocil:ssg-configure_bind_crypto_policy_action:testaction:1</ocil:test_action_ref>90208 ············<ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref>
90221 ··········</ocil:actions>90209 ··········</ocil:actions>
90222 ········</ocil:questionnaire>90210 ········</ocil:questionnaire>
90223 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_sha512_ocil:questionnaire:1">90211 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_ocil:questionnaire:1">
90224 ··········<ocil:title>Sign·kernel·modules·with·SHA-512</ocil:title>90212 ··········<ocil:title>Prevent·Routing·External·Traffic·to·Local·Loopback·on·All·IPv4·Interfaces</ocil:title>
90225 ··········<ocil:actions>90213 ··········<ocil:actions>
90226 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_sha512_action:testaction:1</ocil:test_action_ref>90214 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_action:testaction:1</ocil:test_action_ref>
90227 ··········</ocil:actions>90215 ··········</ocil:actions>
90228 ········</ocil:questionnaire>90216 ········</ocil:questionnaire>
90229 ········<ocil:questionnaire·id="ocil:ssg-dir_ownership_library_dirs_ocil:questionnaire:1">90217 ········<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1">
90230 ··········<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Ownership</ocil:title>90218 ··········<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title>
90231 ··········<ocil:actions>90219 ··········<ocil:actions>
90232 ············<ocil:test_action_ref>ocil:ssg-dir_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>90220 ············<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref>
90233 ··········</ocil:actions>90221 ··········</ocil:actions>
90234 ········</ocil:questionnaire>90222 ········</ocil:questionnaire>
90235 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">90223 ········<ocil:questionnaire·id="ocil:ssg-configure_ssh_crypto_policy_ocil:questionnaire:1">
90236 ··········<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>90224 ··········<ocil:title>Configure·SSH·to·use·System·Crypto·Policy</ocil:title>
90237 ··········<ocil:actions>90225 ··········<ocil:actions>
90238 ············<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>90226 ············<ocil:test_action_ref>ocil:ssg-configure_ssh_crypto_policy_action:testaction:1</ocil:test_action_ref>
90239 ··········</ocil:actions>90227 ··········</ocil:actions>
90240 ········</ocil:questionnaire>90228 ········</ocil:questionnaire>
90241 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">90229 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">
90242 ··········<ocil:title>Verify·Owner·on·cron.weekly</ocil:title>90230 ··········<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>
90243 ··········<ocil:actions>90231 ··········<ocil:actions>
90244 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>90232 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>
90245 ··········</ocil:actions>90233 ··········</ocil:actions>
90246 ········</ocil:questionnaire>90234 ········</ocil:questionnaire>
90247 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_maxstartups_ocil:questionnaire:1">90235 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">
90248 ··········<ocil:title>Ensure·SSH·MaxStartups·is·configured</ocil:title>90236 ··········<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>
90249 ··········<ocil:actions>90237 ··········<ocil:actions>
90250 ············<ocil:test_action_ref>ocil:ssg-sshd_set_maxstartups_action:testaction:1</ocil:test_action_ref>90238 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1044754/1056514 bytes (98.89%) of diff not shown.
985 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ocil.xml
985 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ocil.xml
Ordering differences only
    
Offset 3, 6611 lines modifiedOffset 3, 6605 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1"> 
11 ······<ocil:title>Modify·the·System·Login·Banner</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1"> 
17 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-sudo_require_authentication_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo</ocil:title>11 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sudo_require_authentication_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-package_MFEhiplsm_installed_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-account_unique_name_ocil:questionnaire:1">
29 ······<ocil:title>Install·the·Host·Intrusion·Prevention·System·(HIPS)·Module</ocil:title>17 ······<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·Names</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-package_MFEhiplsm_installed_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-account_unique_name_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1"> 
35 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv4·Interfaces</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1">
 23 ······<ocil:title>Set·Password·Minimum·Age</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-chronyd_server_directive_ocil:questionnaire:1">
41 ······<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>29 ······<ocil:title>Ensure·Chrony·is·only·configured·with·the·server·directive</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-chronyd_server_directive_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1"> 
47 ······<ocil:title>Configure·BIND·to·use·System·Crypto·Policy</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1">
 35 ······<ocil:title>Set·Password·Warning·Age</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-configure_bind_crypto_policy_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_sha512_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_ocil:questionnaire:1">
53 ······<ocil:title>Sign·kernel·modules·with·SHA-512</ocil:title>41 ······<ocil:title>Prevent·Routing·External·Traffic·to·Local·Loopback·on·All·IPv4·Interfaces</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_sha512_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_library_dirs_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1">
59 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Ownership</ocil:title>47 ······<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1"> 
65 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-configure_ssh_crypto_policy_ocil:questionnaire:1">
 53 ······<ocil:title>Configure·SSH·to·use·System·Crypto·Policy</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-configure_ssh_crypto_policy_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Owner·on·cron.weekly</ocil:title>59 ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_maxstartups_ocil:questionnaire:1"> 
77 ······<ocil:title>Ensure·SSH·MaxStartups·is·configured</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">
 65 ······<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sshd_set_maxstartups_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1"> 
83 ······<ocil:title>Ensure·SELinux·is·Not·Disabled</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_audit_configuration_ocil:questionnaire:1">
 71 ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Group·root</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-selinux_not_disabled_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_audit_configuration_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_d_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">
89 ······<ocil:title>Verify·Owner·on·cron.d</ocil:title>77 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_d_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-configure_user_data_backups_ocil:questionnaire:1"> 
95 ······<ocil:title>Configure·Backups·of·User·Data</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1">
 83 ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-configure_user_data_backups_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">
101 ······<ocil:title>Verify·User·Who·Owns·/var/log·Directory</ocil:title>89 ······<ocil:title>Verify·Owner·on·cron.monthly</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">
107 ······<ocil:title>IOMMU·configuration·directive</ocil:title>95 ······<ocil:title>Enable·support·for·BUG()</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-grub2_enable_iommu_force_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-service_rdisc_disabled_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-service_rdisc_disabled_ocil:questionnaire:1">
113 ······<ocil:title>Disable·Network·Router·Discovery·Daemon·(rdisc)</ocil:title>101 ······<ocil:title>Disable·Network·Router·Discovery·Daemon·(rdisc)</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-service_rdisc_disabled_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-service_rdisc_disabled_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands</ocil:title> 
120 ······<ocil:actions> 
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_action:testaction:1</ocil:test_action_ref> 
122 ······</ocil:actions> 
123 ····</ocil:questionnaire> 
Max diff block lines reached; 997249/1008700 bytes (98.86%) of diff not shown.
3.41 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds.xml
3.41 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>
Offset 75, 15 lines modifiedOffset 75, 15 lines modified
75 ······</cpe-dict:cpe-item>75 ······</cpe-dict:cpe-item>
76 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:8">76 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:8">
77 ········<cpe-dict:title·xml:lang="en-us">CentOS·8</cpe-dict:title>77 ········<cpe-dict:title·xml:lang="en-us">CentOS·8</cpe-dict:title>
78 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_centos8:def:1</cpe-dict:check>78 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_centos8:def:1</cpe-dict:check>
79 ······</cpe-dict:cpe-item>79 ······</cpe-dict:cpe-item>
80 ····</cpe-dict:cpe-list>80 ····</cpe-dict:cpe-list>
81 ··</ds:component>81 ··</ds:component>
82 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-02-28T20:08:00">82 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
83 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">83 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
84 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>84 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
85 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>85 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>
86 ······<xccdf-1.2:description>86 ······<xccdf-1.2:description>
87 ········This·guide·presents·a·catalog·of·security-relevant87 ········This·guide·presents·a·catalog·of·security-relevant
88 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of88 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of
89 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)89 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 312766, 15 lines modifiedOffset 312766, 15 lines modified
312766 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>312766 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
312767 ············</xccdf-1.2:check>312767 ············</xccdf-1.2:check>
312768 ··········</xccdf-1.2:Rule>312768 ··········</xccdf-1.2:Rule>
312769 ········</xccdf-1.2:Group>312769 ········</xccdf-1.2:Group>
312770 ······</xccdf-1.2:Group>312770 ······</xccdf-1.2:Group>
312771 ····</xccdf-1.2:Benchmark>312771 ····</xccdf-1.2:Benchmark>
312772 ··</ds:component>312772 ··</ds:component>
312773 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-02-28T20:08:00">312773 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-03-01T22:08:00">
312774 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">312774 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
312775 ······<oval-def:generator>312775 ······<oval-def:generator>
312776 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>312776 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
312777 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>312777 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
312778 ········<oval:schema_version>5.11</oval:schema_version>312778 ········<oval:schema_version>5.11</oval:schema_version>
312779 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>312779 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
312780 ······</oval-def:generator>312780 ······</oval-def:generator>
Offset 379152, 18135 lines modifiedOffset 379152, 18135 lines modified
379152 ············</oval-def:arithmetic>379152 ············</oval-def:arithmetic>
379153 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>379153 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>
379154 ··········</oval-def:arithmetic>379154 ··········</oval-def:arithmetic>
379155 ········</oval-def:local_variable>379155 ········</oval-def:local_variable>
379156 ······</oval-def:variables>379156 ······</oval-def:variables>
379157 ····</oval-def:oval_definitions>379157 ····</oval-def:oval_definitions>
379158 ··</ds:component>379158 ··</ds:component>
379159 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-02-28T20:08:00">379159 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-03-01T22:08:00">
379160 ····<ocil:ocil>379160 ····<ocil:ocil>
379161 ······<ocil:generator>379161 ······<ocil:generator>
379162 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>379162 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
379163 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>379163 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
379164 ········<ocil:schema_version>2.0</ocil:schema_version>379164 ········<ocil:schema_version>2.0</ocil:schema_version>
379165 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>379165 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
379166 ······</ocil:generator>379166 ······</ocil:generator>
379167 ······<ocil:questionnaires>379167 ······<ocil:questionnaires>
379168 ········<ocil:questionnaire·id="ocil:ssg-mount_option_boot_efi_nosuid_ocil:questionnaire:1">379168 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1">
379169 ··········<ocil:title>Add·nosuid·Option·to·/boot/efi</ocil:title>379169 ··········<ocil:title>Verify·User·Who·Owns·Backup·passwd·File</ocil:title>
379170 ··········<ocil:actions>379170 ··········<ocil:actions>
379171 ············<ocil:test_action_ref>ocil:ssg-mount_option_boot_efi_nosuid_action:testaction:1</ocil:test_action_ref>379171 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
379172 ··········</ocil:actions>379172 ··········</ocil:actions>
379173 ········</ocil:questionnaire>379173 ········</ocil:questionnaire>
379174 ········<ocil:questionnaire·id="ocil:ssg-directory_group_ownership_var_log_audit_ocil:questionnaire:1">379174 ········<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1">
379175 ··········<ocil:title>System·Audit·Directories·Must·Be·Group·Owned·By·Root</ocil:title>379175 ··········<ocil:title>Uninstall·rsh-server·Package</ocil:title>
379176 ··········<ocil:actions>379176 ··········<ocil:actions>
379177 ············<ocil:test_action_ref>ocil:ssg-directory_group_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>379177 ············<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref>
379178 ··········</ocil:actions>379178 ··········</ocil:actions>
379179 ········</ocil:questionnaire>379179 ········</ocil:questionnaire>
379180 ········<ocil:questionnaire·id="ocil:ssg-mount_option_home_nosuid_ocil:questionnaire:1">379180 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_ocil:questionnaire:1">
379181 ··········<ocil:title>Add·nosuid·Option·to·/home</ocil:title>379181 ··········<ocil:title>Emulate·Privileged·Access·Never·(PAN)</ocil:title>
379182 ··········<ocil:actions>379182 ··········<ocil:actions>
379183 ············<ocil:test_action_ref>ocil:ssg-mount_option_home_nosuid_action:testaction:1</ocil:test_action_ref>379183 ············<ocil:test_action_ref>ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_action:testaction:1</ocil:test_action_ref>
379184 ··········</ocil:actions>379184 ··········</ocil:actions>
379185 ········</ocil:questionnaire>379185 ········</ocil:questionnaire>
379186 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount_ocil:questionnaire:1">379186 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_login_uids_ocil:questionnaire:1">
379187 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount</ocil:title>379187 ··········<ocil:title>Configure·immutable·Audit·login·UIDs</ocil:title>
379188 ··········<ocil:actions>379188 ··········<ocil:actions>
379189 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount_action:testaction:1</ocil:test_action_ref>379189 ············<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_login_uids_action:testaction:1</ocil:test_action_ref>
379190 ··········</ocil:actions>379190 ··········</ocil:actions>
379191 ········</ocil:questionnaire>379191 ········</ocil:questionnaire>
379192 ········<ocil:questionnaire·id="ocil:ssg-file_etc_security_opasswd_ocil:questionnaire:1">379192 ········<ocil:questionnaire·id="ocil:ssg-selinux_all_devicefiles_labeled_ocil:questionnaire:1">
379193 ··········<ocil:title>Verify·Permissions·and·Ownership·of·Old·Passwords·File</ocil:title>379193 ··········<ocil:title>Ensure·No·Device·Files·are·Unlabeled·by·SELinux</ocil:title>
379194 ··········<ocil:actions>379194 ··········<ocil:actions>
379195 ············<ocil:test_action_ref>ocil:ssg-file_etc_security_opasswd_action:testaction:1</ocil:test_action_ref>379195 ············<ocil:test_action_ref>ocil:ssg-selinux_all_devicefiles_labeled_action:testaction:1</ocil:test_action_ref>
379196 ··········</ocil:actions>379196 ··········</ocil:actions>
379197 ········</ocil:questionnaire>379197 ········</ocil:questionnaire>
379198 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">379198 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1">
379199 ··········<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>379199 ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title>
379200 ··········<ocil:actions>379200 ··········<ocil:actions>
379201 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>379201 ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref>
379202 ··········</ocil:actions>379202 ··········</ocil:actions>
379203 ········</ocil:questionnaire>379203 ········</ocil:questionnaire>
379204 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1">379204 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1">
379205 ··········<ocil:title>Disable·SSH·Support·for·.rhosts·Files</ocil:title>379205 ··········<ocil:title>Configure·audit·according·to·OSPP·requirements</ocil:title>
379206 ··········<ocil:actions>379206 ··········<ocil:actions>
379207 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_action:testaction:1</ocil:test_action_ref>379207 ············<ocil:test_action_ref>ocil:ssg-audit_rules_for_ospp_action:testaction:1</ocil:test_action_ref>
379208 ··········</ocil:actions>379208 ··········</ocil:actions>
379209 ········</ocil:questionnaire>379209 ········</ocil:questionnaire>
379210 ········<ocil:questionnaire·id="ocil:ssg-httpd_enable_system_logging_ocil:questionnaire:1">379210 ········<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">
379211 ··········<ocil:title>Enable·HTTPD·System·Logging</ocil:title>379211 ··········<ocil:title>The·Chrony·package·is·installed</ocil:title>
379212 ··········<ocil:actions>379212 ··········<ocil:actions>
379213 ············<ocil:test_action_ref>ocil:ssg-httpd_enable_system_logging_action:testaction:1</ocil:test_action_ref>379213 ············<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>
379214 ··········</ocil:actions>379214 ··········</ocil:actions>
379215 ········</ocil:questionnaire>379215 ········</ocil:questionnaire>
379216 ········<ocil:questionnaire·id="ocil:ssg-no_legacy_plus_entries_etc_shadow_ocil:questionnaire:1">379216 ········<ocil:questionnaire·id="ocil:ssg-sebool_cobbler_can_network_connect_ocil:questionnaire:1">
379217 ··········<ocil:title>Ensure·there·are·no·legacy·+·NIS·entries·in·/etc/shadow</ocil:title>379217 ··········<ocil:title>Disable·the·cobbler_can_network_connect·SELinux·Boolean</ocil:title>
379218 ··········<ocil:actions>379218 ··········<ocil:actions>
379219 ············<ocil:test_action_ref>ocil:ssg-no_legacy_plus_entries_etc_shadow_action:testaction:1</ocil:test_action_ref>379219 ············<ocil:test_action_ref>ocil:ssg-sebool_cobbler_can_network_connect_action:testaction:1</ocil:test_action_ref>
379220 ··········</ocil:actions>379220 ··········</ocil:actions>
379221 ········</ocil:questionnaire>379221 ········</ocil:questionnaire>
379222 ········<ocil:questionnaire·id="ocil:ssg-service_tftp_disabled_ocil:questionnaire:1">379222 ········<ocil:questionnaire·id="ocil:ssg-package_scap-security-guide_installed_ocil:questionnaire:1">
379223 ··········<ocil:title>Disable·tftp·Service</ocil:title>379223 ··········<ocil:title>Install·scap-security-guide·Package</ocil:title>
379224 ··········<ocil:actions>379224 ··········<ocil:actions>
379225 ············<ocil:test_action_ref>ocil:ssg-service_tftp_disabled_action:testaction:1</ocil:test_action_ref>379225 ············<ocil:test_action_ref>ocil:ssg-package_scap-security-guide_installed_action:testaction:1</ocil:test_action_ref>
379226 ··········</ocil:actions>379226 ··········</ocil:actions>
379227 ········</ocil:questionnaire>379227 ········</ocil:questionnaire>
379228 ········<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_ipsecd_ocil:questionnaire:1">379228 ········<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">
379229 ··········<ocil:title>Verify·User·Who·Owns·/etc/ipsec.d·Directory</ocil:title>379229 ··········<ocil:title>Verify·Owner·on·crontab</ocil:title>
379230 ··········<ocil:actions>379230 ··········<ocil:actions>
Max diff block lines reached; 3568422/3580548 bytes (99.66%) of diff not shown.
2.15 MB
./usr/share/xml/scap/ssg/content/ssg-cs10-ds.xml
2.15 MB
./usr/share/xml/scap/ssg/content/ssg-cs10-ds.xml
    
Offset 19, 27 lines modifiedOffset 19, 27 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:10">32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:10">
33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·10</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·10</cpe-dict:title>
34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_centos10:def:1</cpe-dict:check>34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_centos10:def:1</cpe-dict:check>
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ····</cpe-dict:cpe-list>36 ····</cpe-dict:cpe-list>
37 ··</ds:component>37 ··</ds:component>
38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-02-28T20:08:00">38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>
42 ······<xccdf-1.2:description>42 ······<xccdf-1.2:description>
43 ········This·guide·presents·a·catalog·of·security-relevant43 ········This·guide·presents·a·catalog·of·security-relevant
44 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of44 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of
45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 366, 23 lines modifiedOffset 366, 23 lines modified
366 ··········</cpe-lang:logical-test>366 ··········</cpe-lang:logical-test>
367 ········</cpe-lang:platform>367 ········</cpe-lang:platform>
368 ········<cpe-lang:platform·id="package_bash">368 ········<cpe-lang:platform·id="package_bash">
369 ··········<cpe-lang:logical-test·operator="AND"·negate="false">369 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
370 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>370 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
371 ··········</cpe-lang:logical-test>371 ··········</cpe-lang:logical-test>
372 ········</cpe-lang:platform>372 ········</cpe-lang:platform>
373 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">373 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
374 ··········<cpe-lang:logical-test·operator="AND"·negate="false">374 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
375 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>375 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
376 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
377 ··········</cpe-lang:logical-test>376 ··········</cpe-lang:logical-test>
378 ········</cpe-lang:platform>377 ········</cpe-lang:platform>
379 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">378 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
380 ··········<cpe-lang:logical-test·operator="AND"·negate="false">379 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
381 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>380 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 381 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
382 ··········</cpe-lang:logical-test>382 ··········</cpe-lang:logical-test>
383 ········</cpe-lang:platform>383 ········</cpe-lang:platform>
384 ········<cpe-lang:platform·id="not_s390x_arch">384 ········<cpe-lang:platform·id="not_s390x_arch">
385 ··········<cpe-lang:logical-test·operator="AND"·negate="false">385 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
386 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>386 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
387 ··········</cpe-lang:logical-test>387 ··········</cpe-lang:logical-test>
388 ········</cpe-lang:platform>388 ········</cpe-lang:platform>
Offset 213008, 15 lines modifiedOffset 213008, 15 lines modified
213008 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/>213008 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/>
213009 ············</xccdf-1.2:check>213009 ············</xccdf-1.2:check>
213010 ··········</xccdf-1.2:Rule>213010 ··········</xccdf-1.2:Rule>
213011 ········</xccdf-1.2:Group>213011 ········</xccdf-1.2:Group>
213012 ······</xccdf-1.2:Group>213012 ······</xccdf-1.2:Group>
213013 ····</xccdf-1.2:Benchmark>213013 ····</xccdf-1.2:Benchmark>
213014 ··</ds:component>213014 ··</ds:component>
213015 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-02-28T20:08:00">213015 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-03-01T22:08:00">
213016 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">213016 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
213017 ······<oval-def:generator>213017 ······<oval-def:generator>
213018 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>213018 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
213019 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>213019 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
213020 ········<oval:schema_version>5.11</oval:schema_version>213020 ········<oval:schema_version>5.11</oval:schema_version>
213021 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>213021 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
213022 ······</oval-def:generator>213022 ······</oval-def:generator>
Offset 261685, 13718 lines modifiedOffset 261685, 13907 lines modified
261685 ············</oval-def:arithmetic>261685 ············</oval-def:arithmetic>
261686 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>261686 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
261687 ··········</oval-def:arithmetic>261687 ··········</oval-def:arithmetic>
261688 ········</oval-def:local_variable>261688 ········</oval-def:local_variable>
261689 ······</oval-def:variables>261689 ······</oval-def:variables>
261690 ····</oval-def:oval_definitions>261690 ····</oval-def:oval_definitions>
261691 ··</ds:component>261691 ··</ds:component>
261692 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-02-28T20:08:00">261692 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-03-01T22:08:00">
261693 ····<ocil:ocil>261693 ····<ocil:ocil>
261694 ······<ocil:generator>261694 ······<ocil:generator>
261695 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>261695 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
261696 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>261696 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
261697 ········<ocil:schema_version>2.0</ocil:schema_version>261697 ········<ocil:schema_version>2.0</ocil:schema_version>
261698 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>261698 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
261699 ······</ocil:generator>261699 ······</ocil:generator>
261700 ······<ocil:questionnaires>261700 ······<ocil:questionnaires>
261701 ········<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">261701 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_set_max_life_root_ocil:questionnaire:1">
261702 ··········<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>261702 ··········<ocil:title>Set·Root·Account·Password·Maximum·Age</ocil:title>
261703 ··········<ocil:actions>261703 ··········<ocil:actions>
261704 ············<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>261704 ············<ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_root_action:testaction:1</ocil:test_action_ref>
261705 ··········</ocil:actions>261705 ··········</ocil:actions>
261706 ········</ocil:questionnaire>261706 ········</ocil:questionnaire>
261707 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">261707 ········<ocil:questionnaire·id="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1">
261708 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>261708 ··········<ocil:title>Configure·BIND·to·use·System·Crypto·Policy</ocil:title>
261709 ··········<ocil:actions>261709 ··········<ocil:actions>
261710 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>261710 ············<ocil:test_action_ref>ocil:ssg-configure_bind_crypto_policy_action:testaction:1</ocil:test_action_ref>
261711 ··········</ocil:actions>261711 ··········</ocil:actions>
261712 ········</ocil:questionnaire>261712 ········</ocil:questionnaire>
261713 ········<ocil:questionnaire·id="ocil:ssg-enable_ldap_client_ocil:questionnaire:1">261713 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_user_cfg_ocil:questionnaire:1">
261714 ··········<ocil:title>Enable·the·LDAP·Client·For·Use·in·Authconfig</ocil:title>261714 ··········<ocil:title>Verify·/boot/grub2/user.cfg·Permissions</ocil:title>
261715 ··········<ocil:actions>261715 ··········<ocil:actions>
261716 ············<ocil:test_action_ref>ocil:ssg-enable_ldap_client_action:testaction:1</ocil:test_action_ref>261716 ············<ocil:test_action_ref>ocil:ssg-file_permissions_user_cfg_action:testaction:1</ocil:test_action_ref>
261717 ··········</ocil:actions>261717 ··········</ocil:actions>
261718 ········</ocil:questionnaire>261718 ········</ocil:questionnaire>
261719 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_modules_disabled_ocil:questionnaire:1"> 
261720 ··········<ocil:title>Disable·loading·and·unloading·of·kernel·modules</ocil:title>261719 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_enforce_root_ocil:questionnaire:1">
 261720 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Enforce·for·root·User</ocil:title>
261721 ··········<ocil:actions>261721 ··········<ocil:actions>
261722 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_modules_disabled_action:testaction:1</ocil:test_action_ref>261722 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_enforce_root_action:testaction:1</ocil:test_action_ref>
261723 ··········</ocil:actions>261723 ··········</ocil:actions>
261724 ········</ocil:questionnaire>261724 ········</ocil:questionnaire>
261725 ········<ocil:questionnaire·id="ocil:ssg-mount_option_nosuid_removable_partitions_ocil:questionnaire:1">261725 ········<ocil:questionnaire·id="ocil:ssg-gid_passwd_group_same_ocil:questionnaire:1">
261726 ··········<ocil:title>Add·nosuid·Option·to·Removable·Media·Partitions</ocil:title>261726 ··········<ocil:title>All·GIDs·referenced·in·/etc/passwd·must·be·defined·in·/etc/group</ocil:title>
261727 ··········<ocil:actions>261727 ··········<ocil:actions>
261728 ············<ocil:test_action_ref>ocil:ssg-mount_option_nosuid_removable_partitions_action:testaction:1</ocil:test_action_ref>261728 ············<ocil:test_action_ref>ocil:ssg-gid_passwd_group_same_action:testaction:1</ocil:test_action_ref>
261729 ··········</ocil:actions>261729 ··········</ocil:actions>
261730 ········</ocil:questionnaire>261730 ········</ocil:questionnaire>
261731 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_pkexec_ocil:questionnaire:1">261731 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1">
261732 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·pkexec</ocil:title>261732 ··········<ocil:title>Set·SSH·MaxSessions·limit</ocil:title>
261733 ··········<ocil:actions>261733 ··········<ocil:actions>
261734 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_pkexec_action:testaction:1</ocil:test_action_ref>261734 ············<ocil:test_action_ref>ocil:ssg-sshd_set_max_sessions_action:testaction:1</ocil:test_action_ref>
261735 ··········</ocil:actions>261735 ··········</ocil:actions>
261736 ········</ocil:questionnaire>261736 ········</ocil:questionnaire>
261737 ········<ocil:questionnaire·id="ocil:ssg-grub2_disable_interactive_boot_ocil:questionnaire:1">261737 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1">
261738 ··········<ocil:title>Verify·that·Interactive·Boot·is·Disabled</ocil:title>261738 ··········<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title>
261739 ··········<ocil:actions>261739 ··········<ocil:actions>
261740 ············<ocil:test_action_ref>ocil:ssg-grub2_disable_interactive_boot_action:testaction:1</ocil:test_action_ref>261740 ············<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref>
261741 ··········</ocil:actions>261741 ··········</ocil:actions>
Max diff block lines reached; 2241378/2253327 bytes (99.47%) of diff not shown.
2.5 KB
./usr/share/xml/scap/ssg/content/ssg-cs10-xccdf.xml
2.4 KB
./usr/share/xml/scap/ssg/content/ssg-cs10-xccdf.xml
Ordering differences only
    
Offset 329, 23 lines modifiedOffset 329, 23 lines modified
329 ······</cpe-lang:logical-test>329 ······</cpe-lang:logical-test>
330 ····</cpe-lang:platform>330 ····</cpe-lang:platform>
331 ····<cpe-lang:platform·id="package_bash">331 ····<cpe-lang:platform·id="package_bash">
332 ······<cpe-lang:logical-test·operator="AND"·negate="false">332 ······<cpe-lang:logical-test·operator="AND"·negate="false">
333 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>333 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
334 ······</cpe-lang:logical-test>334 ······</cpe-lang:logical-test>
335 ····</cpe-lang:platform>335 ····</cpe-lang:platform>
336 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">336 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
337 ······<cpe-lang:logical-test·operator="AND"·negate="false">337 ······<cpe-lang:logical-test·operator="AND"·negate="false">
338 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>338 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
339 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
340 ······</cpe-lang:logical-test>339 ······</cpe-lang:logical-test>
341 ····</cpe-lang:platform>340 ····</cpe-lang:platform>
342 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">341 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
343 ······<cpe-lang:logical-test·operator="AND"·negate="false">342 ······<cpe-lang:logical-test·operator="AND"·negate="false">
344 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>343 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 344 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
345 ······</cpe-lang:logical-test>345 ······</cpe-lang:logical-test>
346 ····</cpe-lang:platform>346 ····</cpe-lang:platform>
347 ····<cpe-lang:platform·id="not_s390x_arch">347 ····<cpe-lang:platform·id="not_s390x_arch">
348 ······<cpe-lang:logical-test·operator="AND"·negate="false">348 ······<cpe-lang:logical-test·operator="AND"·negate="false">
349 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>349 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
350 ······</cpe-lang:logical-test>350 ······</cpe-lang:logical-test>
351 ····</cpe-lang:platform>351 ····</cpe-lang:platform>
3.29 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds.xml
3.29 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds.xml
    
Offset 19, 27 lines modifiedOffset 19, 27 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:9">32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:9">
33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·9</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·9</cpe-dict:title>
34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_centos9:def:1</cpe-dict:check>34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_centos9:def:1</cpe-dict:check>
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ····</cpe-dict:cpe-list>36 ····</cpe-dict:cpe-list>
37 ··</ds:component>37 ··</ds:component>
38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-02-28T20:08:00">38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>
42 ······<xccdf-1.2:description>42 ······<xccdf-1.2:description>
43 ········This·guide·presents·a·catalog·of·security-relevant43 ········This·guide·presents·a·catalog·of·security-relevant
44 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of44 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of
45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 305658, 15 lines modifiedOffset 305658, 15 lines modified
305658 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>305658 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
305659 ············</xccdf-1.2:check>305659 ············</xccdf-1.2:check>
305660 ··········</xccdf-1.2:Rule>305660 ··········</xccdf-1.2:Rule>
305661 ········</xccdf-1.2:Group>305661 ········</xccdf-1.2:Group>
305662 ······</xccdf-1.2:Group>305662 ······</xccdf-1.2:Group>
305663 ····</xccdf-1.2:Benchmark>305663 ····</xccdf-1.2:Benchmark>
305664 ··</ds:component>305664 ··</ds:component>
305665 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-02-28T20:08:00">305665 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-03-01T22:08:00">
305666 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">305666 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
305667 ······<oval-def:generator>305667 ······<oval-def:generator>
305668 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>305668 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
305669 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>305669 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
305670 ········<oval:schema_version>5.11</oval:schema_version>305670 ········<oval:schema_version>5.11</oval:schema_version>
305671 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>305671 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
305672 ······</oval-def:generator>305672 ······</oval-def:generator>
Offset 371382, 20441 lines modifiedOffset 371382, 20442 lines modified
371382 ············</oval-def:arithmetic>371382 ············</oval-def:arithmetic>
371383 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>371383 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
371384 ··········</oval-def:arithmetic>371384 ··········</oval-def:arithmetic>
371385 ········</oval-def:local_variable>371385 ········</oval-def:local_variable>
371386 ······</oval-def:variables>371386 ······</oval-def:variables>
371387 ····</oval-def:oval_definitions>371387 ····</oval-def:oval_definitions>
371388 ··</ds:component>371388 ··</ds:component>
371389 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-02-28T20:08:00">371389 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-03-01T22:08:00">
371390 ····<ocil:ocil>371390 ····<ocil:ocil>
371391 ······<ocil:generator>371391 ······<ocil:generator>
371392 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>371392 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
371393 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>371393 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
371394 ········<ocil:schema_version>2.0</ocil:schema_version>371394 ········<ocil:schema_version>2.0</ocil:schema_version>
371395 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>371395 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
371396 ······</ocil:generator>371396 ······</ocil:generator>
371397 ······<ocil:questionnaires>371397 ······<ocil:questionnaires>
371398 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_drop_in_config_ocil:questionnaire:1">371398 ········<ocil:questionnaire·id="ocil:ssg-file_audit_tools_group_ownership_ocil:questionnaire:1">
371399 ··········<ocil:title>Verify·Permissions·on·SSH·Server·Config·File</ocil:title>371399 ··········<ocil:title>Audit·Tools·Must·Be·Group-owned·by·Root</ocil:title>
371400 ··········<ocil:actions>371400 ··········<ocil:actions>
371401 ············<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_drop_in_config_action:testaction:1</ocil:test_action_ref>371401 ············<ocil:test_action_ref>ocil:ssg-file_audit_tools_group_ownership_action:testaction:1</ocil:test_action_ref>
371402 ··········</ocil:actions>371402 ··········</ocil:actions>
371403 ········</ocil:questionnaire>371403 ········</ocil:questionnaire>
371404 ········<ocil:questionnaire·id="ocil:ssg-sebool_git_cgi_enable_homedirs_ocil:questionnaire:1">371404 ········<ocil:questionnaire·id="ocil:ssg-sebool_httpd_ssi_exec_ocil:questionnaire:1">
371405 ··········<ocil:title>Disable·the·git_cgi_enable_homedirs·SELinux·Boolean</ocil:title>371405 ··········<ocil:title>Disable·the·httpd_ssi_exec·SELinux·Boolean</ocil:title>
371406 ··········<ocil:actions>371406 ··········<ocil:actions>
371407 ············<ocil:test_action_ref>ocil:ssg-sebool_git_cgi_enable_homedirs_action:testaction:1</ocil:test_action_ref>371407 ············<ocil:test_action_ref>ocil:ssg-sebool_httpd_ssi_exec_action:testaction:1</ocil:test_action_ref>
371408 ··········</ocil:actions>371408 ··········</ocil:actions>
371409 ········</ocil:questionnaire>371409 ········</ocil:questionnaire>
371410 ········<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">371410 ········<ocil:questionnaire·id="ocil:ssg-sebool_exim_read_user_files_ocil:questionnaire:1">
371411 ··········<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>371411 ··········<ocil:title>Disable·the·exim_read_user_files·SELinux·Boolean</ocil:title>
371412 ··········<ocil:actions>371412 ··········<ocil:actions>
371413 ············<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>371413 ············<ocil:test_action_ref>ocil:ssg-sebool_exim_read_user_files_action:testaction:1</ocil:test_action_ref>
371414 ··········</ocil:actions>371414 ··········</ocil:actions>
371415 ········</ocil:questionnaire>371415 ········</ocil:questionnaire>
371416 ········<ocil:questionnaire·id="ocil:ssg-audit_access_success_aarch64_ocil:questionnaire:1">371416 ········<ocil:questionnaire·id="ocil:ssg-file_cron_allow_exists_ocil:questionnaire:1">
371417 ··········<ocil:title>Configure·auditing·of·successful·file·accesses·(AArch64)</ocil:title>371417 ··········<ocil:title>Ensure·that·/etc/cron.allow·exists</ocil:title>
371418 ··········<ocil:actions>371418 ··········<ocil:actions>
371419 ············<ocil:test_action_ref>ocil:ssg-audit_access_success_aarch64_action:testaction:1</ocil:test_action_ref>371419 ············<ocil:test_action_ref>ocil:ssg-file_cron_allow_exists_action:testaction:1</ocil:test_action_ref>
371420 ··········</ocil:actions>371420 ··········</ocil:actions>
371421 ········</ocil:questionnaire>371421 ········</ocil:questionnaire>
371422 ········<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">371422 ········<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1">
371423 ··········<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>371423 ··········<ocil:title>Enable·cron·Service</ocil:title>
371424 ··········<ocil:actions>371424 ··········<ocil:actions>
371425 ············<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>371425 ············<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref>
371426 ··········</ocil:actions>371426 ··········</ocil:actions>
371427 ········</ocil:questionnaire>371427 ········</ocil:questionnaire>
371428 ········<ocil:questionnaire·id="ocil:ssg-sebool_httpd_run_stickshift_ocil:questionnaire:1">371428 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1">
371429 ··········<ocil:title>Disable·the·httpd_run_stickshift·SELinux·Boolean</ocil:title>371429 ··········<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title>
371430 ··········<ocil:actions>371430 ··········<ocil:actions>
371431 ············<ocil:test_action_ref>ocil:ssg-sebool_httpd_run_stickshift_action:testaction:1</ocil:test_action_ref>371431 ············<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref>
371432 ··········</ocil:actions>371432 ··········</ocil:actions>
371433 ········</ocil:questionnaire>371433 ········</ocil:questionnaire>
371434 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_syn_cookies_ocil:questionnaire:1"> 
371435 ··········<ocil:title>Enable·TCP/IP·syncookie·support</ocil:title>371434 ········<ocil:questionnaire·id="ocil:ssg-audit_modify_failed_ppc64le_ocil:questionnaire:1">
 371435 ··········<ocil:title>Configure·auditing·of·unsuccessful·file·modifications·(ppc64le)</ocil:title>
371436 ··········<ocil:actions>371436 ··········<ocil:actions>
371437 ············<ocil:test_action_ref>ocil:ssg-kernel_config_syn_cookies_action:testaction:1</ocil:test_action_ref>371437 ············<ocil:test_action_ref>ocil:ssg-audit_modify_failed_ppc64le_action:testaction:1</ocil:test_action_ref>
371438 ··········</ocil:actions>371438 ··········</ocil:actions>
371439 ········</ocil:questionnaire>371439 ········</ocil:questionnaire>
371440 ········<ocil:questionnaire·id="ocil:ssg-sssd_certificate_verification_ocil:questionnaire:1">371440 ········<ocil:questionnaire·id="ocil:ssg-sebool_httpd_can_network_relay_ocil:questionnaire:1">
371441 ··········<ocil:title>Certificate·status·checking·in·SSSD</ocil:title>371441 ··········<ocil:title>Disable·the·httpd_can_network_relay·SELinux·Boolean</ocil:title>
371442 ··········<ocil:actions>371442 ··········<ocil:actions>
371443 ············<ocil:test_action_ref>ocil:ssg-sssd_certificate_verification_action:testaction:1</ocil:test_action_ref>371443 ············<ocil:test_action_ref>ocil:ssg-sebool_httpd_can_network_relay_action:testaction:1</ocil:test_action_ref>
371444 ··········</ocil:actions>371444 ··········</ocil:actions>
371445 ········</ocil:questionnaire>371445 ········</ocil:questionnaire>
371446 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">371446 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_issue_net_ocil:questionnaire:1">
371447 ··········<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>371447 ··········<ocil:title>Verify·Group·Ownership·of·System·Login·Banner·for·Remote·Connections</ocil:title>
371448 ··········<ocil:actions>371448 ··········<ocil:actions>
371449 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>371449 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_net_action:testaction:1</ocil:test_action_ref>
371450 ··········</ocil:actions>371450 ··········</ocil:actions>
371451 ········</ocil:questionnaire>371451 ········</ocil:questionnaire>
371452 ········<ocil:questionnaire·id="ocil:ssg-sebool_mount_anyfile_ocil:questionnaire:1">371452 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_binaries_ocil:questionnaire:1">
371453 ··········<ocil:title>Enable·the·mount_anyfile·SELinux·Boolean</ocil:title>371453 ··········<ocil:title>Verify·that·audit·tools·are·owned·by·root</ocil:title>
371454 ··········<ocil:actions>371454 ··········<ocil:actions>
371455 ············<ocil:test_action_ref>ocil:ssg-sebool_mount_anyfile_action:testaction:1</ocil:test_action_ref>371455 ············<ocil:test_action_ref>ocil:ssg-file_ownership_audit_binaries_action:testaction:1</ocil:test_action_ref>
371456 ··········</ocil:actions>371456 ··········</ocil:actions>
371457 ········</ocil:questionnaire>371457 ········</ocil:questionnaire>
371458 ········<ocil:questionnaire·id="ocil:ssg-file_groupownership_audit_binaries_ocil:questionnaire:1">371458 ········<ocil:questionnaire·id="ocil:ssg-package_geolite2-city_removed_ocil:questionnaire:1">
371459 ··········<ocil:title>Verify·that·audit·tools·are·owned·by·group·root</ocil:title>371459 ··········<ocil:title>Uninstall·geolite2-city·Package</ocil:title>
371460 ··········<ocil:actions>371460 ··········<ocil:actions>
371461 ············<ocil:test_action_ref>ocil:ssg-file_groupownership_audit_binaries_action:testaction:1</ocil:test_action_ref>371461 ············<ocil:test_action_ref>ocil:ssg-package_geolite2-city_removed_action:testaction:1</ocil:test_action_ref>
371462 ··········</ocil:actions>371462 ··········</ocil:actions>
371463 ········</ocil:questionnaire>371463 ········</ocil:questionnaire>
Max diff block lines reached; 3438251/3450600 bytes (99.64%) of diff not shown.
2.05 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds.xml
2.05 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:39">28 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:39">
29 ········<cpe-dict:title·xml:lang="en-us">Fedora·39</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Fedora·39</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:40">32 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:40">
33 ········<cpe-dict:title·xml:lang="en-us">Fedora·40</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Fedora·40</cpe-dict:title>
Offset 51, 15 lines modifiedOffset 51, 15 lines modified
51 ······</cpe-dict:cpe-item>51 ······</cpe-dict:cpe-item>
52 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:45">52 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:45">
53 ········<cpe-dict:title·xml:lang="en-us">Fedora·45</cpe-dict:title>53 ········<cpe-dict:title·xml:lang="en-us">Fedora·45</cpe-dict:title>
54 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>54 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>
55 ······</cpe-dict:cpe-item>55 ······</cpe-dict:cpe-item>
56 ····</cpe-dict:cpe-list>56 ····</cpe-dict:cpe-list>
57 ··</ds:component>57 ··</ds:component>
58 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-xccdf.xml"·timestamp="2025-02-28T20:08:00">58 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-xccdf.xml"·timestamp="2025-03-01T22:08:00">
59 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FEDORA"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">59 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FEDORA"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
60 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>60 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
61 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Fedora</xccdf-1.2:title>61 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Fedora</xccdf-1.2:title>
62 ······<xccdf-1.2:description>62 ······<xccdf-1.2:description>
63 ········This·guide·presents·a·catalog·of·security-relevant63 ········This·guide·presents·a·catalog·of·security-relevant
64 configuration·settings·for·Fedora.·It·is·a·rendering·of64 configuration·settings·for·Fedora.·It·is·a·rendering·of
65 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)65 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 224264, 15 lines modifiedOffset 224264, 15 lines modified
224264 ··············<xccdf-1.2:check-content-ref·href="ssg-fedora-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>224264 ··············<xccdf-1.2:check-content-ref·href="ssg-fedora-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>
224265 ············</xccdf-1.2:check>224265 ············</xccdf-1.2:check>
224266 ··········</xccdf-1.2:Rule>224266 ··········</xccdf-1.2:Rule>
224267 ········</xccdf-1.2:Group>224267 ········</xccdf-1.2:Group>
224268 ······</xccdf-1.2:Group>224268 ······</xccdf-1.2:Group>
224269 ····</xccdf-1.2:Benchmark>224269 ····</xccdf-1.2:Benchmark>
224270 ··</ds:component>224270 ··</ds:component>
224271 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-oval.xml"·timestamp="2025-02-28T20:08:00">224271 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-oval.xml"·timestamp="2025-03-01T22:08:00">
224272 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">224272 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
224273 ······<oval-def:generator>224273 ······<oval-def:generator>
224274 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>224274 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
224275 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>224275 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
224276 ········<oval:schema_version>5.11</oval:schema_version>224276 ········<oval:schema_version>5.11</oval:schema_version>
224277 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>224277 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
224278 ······</oval-def:generator>224278 ······</oval-def:generator>
Offset 273035, 11149 lines modifiedOffset 273035, 11149 lines modified
273035 ············</oval-def:arithmetic>273035 ············</oval-def:arithmetic>
273036 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>273036 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>
273037 ··········</oval-def:arithmetic>273037 ··········</oval-def:arithmetic>
273038 ········</oval-def:local_variable>273038 ········</oval-def:local_variable>
273039 ······</oval-def:variables>273039 ······</oval-def:variables>
273040 ····</oval-def:oval_definitions>273040 ····</oval-def:oval_definitions>
273041 ··</ds:component>273041 ··</ds:component>
273042 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-ocil.xml"·timestamp="2025-02-28T20:08:00">273042 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-ocil.xml"·timestamp="2025-03-01T22:08:00">
273043 ····<ocil:ocil>273043 ····<ocil:ocil>
273044 ······<ocil:generator>273044 ······<ocil:generator>
273045 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>273045 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
273046 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>273046 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
273047 ········<ocil:schema_version>2.0</ocil:schema_version>273047 ········<ocil:schema_version>2.0</ocil:schema_version>
273048 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>273048 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
273049 ······</ocil:generator>273049 ······</ocil:generator>
273050 ······<ocil:questionnaires>273050 ······<ocil:questionnaires>
273051 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_ocil:questionnaire:1"> 
273052 ··········<ocil:title>Record·Unsuccessful·Delete·Attempts·to·Files·-·unlink</ocil:title>273051 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1">
 273052 ··········<ocil:title>Verify·Group·Who·Owns·cron.hourly</ocil:title>
273053 ··········<ocil:actions>273053 ··········<ocil:actions>
273054 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_action:testaction:1</ocil:test_action_ref>273054 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref>
273055 ··········</ocil:actions>273055 ··········</ocil:actions>
273056 ········</ocil:questionnaire>273056 ········</ocil:questionnaire>
273057 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1">273057 ········<ocil:questionnaire·id="ocil:ssg-package_rsyslog-gnutls_installed_ocil:questionnaire:1">
273058 ··········<ocil:title>Verify·Group·Who·Owns·/var/log/messages·File</ocil:title>273058 ··········<ocil:title>Ensure·rsyslog-gnutls·is·installed</ocil:title>
273059 ··········<ocil:actions>273059 ··········<ocil:actions>
273060 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_messages_action:testaction:1</ocil:test_action_ref>273060 ············<ocil:test_action_ref>ocil:ssg-package_rsyslog-gnutls_installed_action:testaction:1</ocil:test_action_ref>
273061 ··········</ocil:actions>273061 ··········</ocil:actions>
273062 ········</ocil:questionnaire>273062 ········</ocil:questionnaire>
273063 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_ocil:questionnaire:1"> 
273064 ··········<ocil:title>Record·Successful·Access·Attempts·to·Files·-·open_by_handle_at</ocil:title>273063 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_wifi_notification_ocil:questionnaire:1">
 273064 ··········<ocil:title>Disable·WIFI·Network·Notification·in·GNOME3</ocil:title>
273065 ··········<ocil:actions>273065 ··········<ocil:actions>
273066 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_action:testaction:1</ocil:test_action_ref>273066 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_wifi_notification_action:testaction:1</ocil:test_action_ref>
273067 ··········</ocil:actions>273067 ··········</ocil:actions>
273068 ········</ocil:questionnaire>273068 ········</ocil:questionnaire>
273069 ········<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1"> 
273070 ··········<ocil:title>Configure·Polyinstantiation·of·/var/tmp·Directories</ocil:title>273069 ········<ocil:questionnaire·id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1">
 273070 ··········<ocil:title>Deactivate·Wireless·Network·Interfaces</ocil:title>
273071 ··········<ocil:actions>273071 ··········<ocil:actions>
273072 ············<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_var_tmp_action:testaction:1</ocil:test_action_ref>273072 ············<ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref>
273073 ··········</ocil:actions>273073 ··········</ocil:actions>
273074 ········</ocil:questionnaire>273074 ········</ocil:questionnaire>
273075 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1">273075 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_automount_ocil:questionnaire:1">
273076 ··········<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>273076 ··········<ocil:title>Disable·GNOME3·Automounting</ocil:title>
273077 ··········<ocil:actions>273077 ··········<ocil:actions>
273078 ············<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>273078 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_automount_action:testaction:1</ocil:test_action_ref>
273079 ··········</ocil:actions>273079 ··········</ocil:actions>
273080 ········</ocil:questionnaire>273080 ········</ocil:questionnaire>
273081 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_ocil:questionnaire:1"> 
273082 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open_by_handle_at</ocil:title>273081 ········<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1">
 273082 ··········<ocil:title>Enable·cron·Service</ocil:title>
273083 ··········<ocil:actions>273083 ··········<ocil:actions>
273084 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_action:testaction:1</ocil:test_action_ref>273084 ············<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref>
273085 ··········</ocil:actions>273085 ··········</ocil:actions>
273086 ········</ocil:questionnaire>273086 ········</ocil:questionnaire>
273087 ········<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">273087 ········<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1">
273088 ··········<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>273088 ··········<ocil:title>Remove·NIS·Client</ocil:title>
273089 ··········<ocil:actions>273089 ··········<ocil:actions>
273090 ············<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>273090 ············<ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref>
273091 ··········</ocil:actions>273091 ··········</ocil:actions>
273092 ········</ocil:questionnaire>273092 ········</ocil:questionnaire>
273093 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_access_monitoring_ocil:questionnaire:1"> 
273094 ··········<ocil:title>Ensure·remote·access·methods·are·monitored·in·Rsyslog</ocil:title>273093 ········<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_logindefs_ocil:questionnaire:1">
 273094 ··········<ocil:title>Set·Password·Hashing·Algorithm·in·/etc/login.defs</ocil:title>
273095 ··········<ocil:actions>273095 ··········<ocil:actions>
273096 ············<ocil:test_action_ref>ocil:ssg-rsyslog_remote_access_monitoring_action:testaction:1</ocil:test_action_ref>273096 ············<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_logindefs_action:testaction:1</ocil:test_action_ref>
273097 ··········</ocil:actions>273097 ··········</ocil:actions>
273098 ········</ocil:questionnaire>273098 ········</ocil:questionnaire>
273099 ········<ocil:questionnaire·id="ocil:ssg-sysctl_crypto_fips_enabled_ocil:questionnaire:1">273099 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_etc_group_open_by_handle_at_ocil:questionnaire:1">
273100 ··········<ocil:title>Set·kernel·parameter·'crypto.fips_enabled'·to·1</ocil:title>273100 ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·via·open_by_handle_at·syscall·-·/etc/group</ocil:title>
273101 ··········<ocil:actions>273101 ··········<ocil:actions>
273102 ············<ocil:test_action_ref>ocil:ssg-sysctl_crypto_fips_enabled_action:testaction:1</ocil:test_action_ref>273102 ············<ocil:test_action_ref>ocil:ssg-audit_rules_etc_group_open_by_handle_at_action:testaction:1</ocil:test_action_ref>
273103 ··········</ocil:actions>273103 ··········</ocil:actions>
273104 ········</ocil:questionnaire>273104 ········</ocil:questionnaire>
273105 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1">273105 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1">
273106 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title>273106 ··········<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title>
273107 ··········<ocil:actions>273107 ··········<ocil:actions>
273108 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref>273108 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 2139442/2151228 bytes (99.45%) of diff not shown.
1.96 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ocil.xml
1.96 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ocil.xml
Ordering differences only
    
Offset 3, 11140 lines modifiedOffset 3, 11140 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_ocil:questionnaire:1"> 
11 ······<ocil:title>Record·Unsuccessful·Delete·Attempts·to·Files·-·unlink</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1">
 11 ······<ocil:title>Verify·Group·Who·Owns·cron.hourly</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1"> 
17 ······<ocil:title>Verify·Group·Who·Owns·/var/log/messages·File</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog-gnutls_installed_ocil:questionnaire:1">
 17 ······<ocil:title>Ensure·rsyslog-gnutls·is·installed</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_messages_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-package_rsyslog-gnutls_installed_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_ocil:questionnaire:1"> 
23 ······<ocil:title>Record·Successful·Access·Attempts·to·Files·-·open_by_handle_at</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_wifi_notification_ocil:questionnaire:1">
 23 ······<ocil:title>Disable·WIFI·Network·Notification·in·GNOME3</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_wifi_notification_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1"> 
29 ······<ocil:title>Configure·Polyinstantiation·of·/var/tmp·Directories</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1">
 29 ······<ocil:title>Deactivate·Wireless·Network·Interfaces</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_var_tmp_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1"> 
35 ······<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_automount_ocil:questionnaire:1">
 35 ······<ocil:title>Disable·GNOME3·Automounting</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_automount_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_ocil:questionnaire:1"> 
41 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open_by_handle_at</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1">
 41 ······<ocil:title>Enable·cron·Service</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1">
47 ······<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>47 ······<ocil:title>Remove·NIS·Client</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_access_monitoring_ocil:questionnaire:1"> 
53 ······<ocil:title>Ensure·remote·access·methods·are·monitored·in·Rsyslog</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_logindefs_ocil:questionnaire:1">
 53 ······<ocil:title>Set·Password·Hashing·Algorithm·in·/etc/login.defs</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-rsyslog_remote_access_monitoring_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_logindefs_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_crypto_fips_enabled_ocil:questionnaire:1"> 
59 ······<ocil:title>Set·kernel·parameter·'crypto.fips_enabled'·to·1</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_etc_group_open_by_handle_at_ocil:questionnaire:1">
 59 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·via·open_by_handle_at·syscall·-·/etc/group</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sysctl_crypto_fips_enabled_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_etc_group_open_by_handle_at_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1">
65 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title>65 ······<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1"> 
71 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv4·Interfaces</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_ftruncate_ocil:questionnaire:1">
 71 ······<ocil:title>Record·Successful·Access·Attempts·to·Files·-·ftruncate</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-accounts_authorized_local_users_ocil:questionnaire:1"> 
77 ······<ocil:title>Only·Authorized·Local·User·Accounts·Exist·on·Operating·System</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_audit_auditd_ocil:questionnaire:1">
 77 ······<ocil:title>Verify·Permissions·on·/etc/audit/auditd.conf</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-accounts_authorized_local_users_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_audit_auditd_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-service_chronyd_or_ntpd_enabled_ocil:questionnaire:1"> 
83 ······<ocil:title>Enable·the·NTP·Daemon</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_trunc_write_ocil:questionnaire:1">
 83 ······<ocil:title>Record·Unsuccessful·Modification·Attempts·to·Files·-·open·O_TRUNC_WRITE</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-service_chronyd_or_ntpd_enabled_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_trunc_write_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_ocil:questionnaire:1"> 
89 ······<ocil:title>Limit·Password·Reuse:·system-auth</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_motd_ocil:questionnaire:1">
 89 ······<ocil:title>Modify·the·System·Message·of·the·Day·Banner</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-banner_etc_motd_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy_ocil:questionnaire:1"> 
95 ······<ocil:title>Configure·SSH·Client·to·Use·FIPS·140·Validated·Ciphers:·openssh.config</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1">
 95 ······<ocil:title>Enable·automatic·signing·of·all·modules</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_all_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_userhelper_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_su_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·userhelper</ocil:title>101 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·su</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_userhelper_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_su_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nodev_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-sshd_x11_use_localhost_ocil:questionnaire:1">
107 ······<ocil:title>Add·nodev·Option·to·/home</ocil:title>107 ······<ocil:title>Prevent·remote·hosts·from·connecting·to·the·proxy·display</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nodev_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sshd_x11_use_localhost_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_rmmod_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·rmmod</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_ocil:questionnaire:1">
 113 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_rmmod_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 2046547/2059039 bytes (99.39%) of diff not shown.
243 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ds.xml
243 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP1:ga:server">28 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP1:ga:server">
29 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP1</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP1</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP2:ga:server">32 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP2:ga:server">
33 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP2</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP2</cpe-dict:title>
Offset 35, 15 lines modifiedOffset 35, 15 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP3:ga:server">36 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP3:ga:server">
37 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP3</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP3</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-xccdf.xml"·timestamp="2025-02-28T20:08:00">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_KYLINSERVER10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_KYLINSERVER10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Kylin·Server·10</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Kylin·Server·10</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·Kylin·Server·10.·It·is·a·rendering·of48 configuration·settings·for·Kylin·Server·10.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 20889, 15 lines modifiedOffset 20889, 15 lines modified
20889 ··············<xccdf-1.2:check-content-ref·href="ssg-kylinserver10-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1"/>20889 ··············<xccdf-1.2:check-content-ref·href="ssg-kylinserver10-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1"/>
20890 ············</xccdf-1.2:check>20890 ············</xccdf-1.2:check>
20891 ··········</xccdf-1.2:Rule>20891 ··········</xccdf-1.2:Rule>
20892 ········</xccdf-1.2:Group>20892 ········</xccdf-1.2:Group>
20893 ······</xccdf-1.2:Group>20893 ······</xccdf-1.2:Group>
20894 ····</xccdf-1.2:Benchmark>20894 ····</xccdf-1.2:Benchmark>
20895 ··</ds:component>20895 ··</ds:component>
20896 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"·timestamp="2025-02-28T20:08:00">20896 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"·timestamp="2025-03-01T22:08:00">
20897 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">20897 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
20898 ······<oval-def:generator>20898 ······<oval-def:generator>
20899 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>20899 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
20900 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>20900 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
20901 ········<oval:schema_version>5.11</oval:schema_version>20901 ········<oval:schema_version>5.11</oval:schema_version>
20902 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>20902 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
20903 ······</oval-def:generator>20903 ······</oval-def:generator>
Offset 26495, 1671 lines modifiedOffset 26495, 1654 lines modified
26495 ············</oval-def:arithmetic>26495 ············</oval-def:arithmetic>
26496 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>26496 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
26497 ··········</oval-def:arithmetic>26497 ··········</oval-def:arithmetic>
26498 ········</oval-def:local_variable>26498 ········</oval-def:local_variable>
26499 ······</oval-def:variables>26499 ······</oval-def:variables>
26500 ····</oval-def:oval_definitions>26500 ····</oval-def:oval_definitions>
26501 ··</ds:component>26501 ··</ds:component>
26502 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"·timestamp="2025-02-28T20:08:00">26502 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"·timestamp="2025-03-01T22:08:00">
26503 ····<ocil:ocil>26503 ····<ocil:ocil>
26504 ······<ocil:generator>26504 ······<ocil:generator>
26505 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>26505 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
26506 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>26506 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
26507 ········<ocil:schema_version>2.0</ocil:schema_version>26507 ········<ocil:schema_version>2.0</ocil:schema_version>
26508 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>26508 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
26509 ······</ocil:generator>26509 ······</ocil:generator>
26510 ······<ocil:questionnaires>26510 ······<ocil:questionnaires>
 26511 ········<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1">
 26512 ··········<ocil:title>Set·Lockout·Time·for·Failed·Password·Attempts</ocil:title>
26511 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1"> 
26512 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title> 
26513 ··········<ocil:actions> 
26514 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref> 
26515 ··········</ocil:actions> 
26516 ········</ocil:questionnaire> 
26517 ········<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1"> 
26518 ··········<ocil:title>Limit·Users'·SSH·Access</ocil:title> 
26519 ··········<ocil:actions> 
26520 ············<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref> 
26521 ··········</ocil:actions> 
26522 ········</ocil:questionnaire> 
26523 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1"> 
26524 ··········<ocil:title>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</ocil:title> 
26525 ··········<ocil:actions> 
26526 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1</ocil:test_action_ref> 
26527 ··········</ocil:actions> 
26528 ········</ocil:questionnaire> 
26529 ········<ocil:questionnaire·id="ocil:ssg-package_telnet-server_removed_ocil:questionnaire:1"> 
26530 ··········<ocil:title>Uninstall·telnet-server·Package</ocil:title> 
26531 ··········<ocil:actions>26513 ··········<ocil:actions>
26532 ············<ocil:test_action_ref>ocil:ssg-package_telnet-server_removed_action:testaction:1</ocil:test_action_ref>26514 ············<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_unlock_time_action:testaction:1</ocil:test_action_ref>
26533 ··········</ocil:actions>26515 ··········</ocil:actions>
26534 ········</ocil:questionnaire>26516 ········</ocil:questionnaire>
26535 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minlen_ocil:questionnaire:1">26517 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_lcredit_ocil:questionnaire:1">
26536 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Length</ocil:title>26518 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Lowercase·Characters</ocil:title>
26537 ··········<ocil:actions>26519 ··········<ocil:actions>
26538 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minlen_action:testaction:1</ocil:test_action_ref>26520 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_lcredit_action:testaction:1</ocil:test_action_ref>
26539 ··········</ocil:actions>26521 ··········</ocil:actions>
26540 ········</ocil:questionnaire>26522 ········</ocil:questionnaire>
26541 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_unix_remember_ocil:questionnaire:1">26523 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ocredit_ocil:questionnaire:1">
26542 ··········<ocil:title>Limit·Password·Reuse</ocil:title>26524 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Special·Characters</ocil:title>
26543 ··········<ocil:actions>26525 ··········<ocil:actions>
26544 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_remember_action:testaction:1</ocil:test_action_ref>26526 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ocredit_action:testaction:1</ocil:test_action_ref>
26545 ··········</ocil:actions>26527 ··········</ocil:actions>
26546 ········</ocil:questionnaire>26528 ········</ocil:questionnaire>
26547 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"> 
26548 ··········<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title>26529 ········<ocil:questionnaire·id="ocil:ssg-require_emergency_target_auth_ocil:questionnaire:1">
 26530 ··········<ocil:title>Require·Authentication·for·Emergency·Systemd·Target</ocil:title>
26549 ··········<ocil:actions>26531 ··········<ocil:actions>
26550 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>26532 ············<ocil:test_action_ref>ocil:ssg-require_emergency_target_auth_action:testaction:1</ocil:test_action_ref>
26551 ··········</ocil:actions>26533 ··········</ocil:actions>
26552 ········</ocil:questionnaire>26534 ········</ocil:questionnaire>
26553 ········<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_deny_ocil:questionnaire:1">26535 ········<ocil:questionnaire·id="ocil:ssg-grub2_password_ocil:questionnaire:1">
26554 ··········<ocil:title>Lock·Accounts·After·Failed·Password·Attempts</ocil:title>26536 ··········<ocil:title>Set·Boot·Loader·Password·in·grub2</ocil:title>
26555 ··········<ocil:actions>26537 ··········<ocil:actions>
26556 ············<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_deny_action:testaction:1</ocil:test_action_ref>26538 ············<ocil:test_action_ref>ocil:ssg-grub2_password_action:testaction:1</ocil:test_action_ref>
26557 ··········</ocil:actions>26539 ··········</ocil:actions>
26558 ········</ocil:questionnaire>26540 ········</ocil:questionnaire>
26559 ········<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1">26541 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1">
26560 ··········<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title>26542 ··········<ocil:title>Configure·auditd·space_left·on·Low·Disk·Space</ocil:title>
26561 ··········<ocil:actions>26543 ··········<ocil:actions>
26562 ············<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref>26544 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action:testaction:1</ocil:test_action_ref>
26563 ··········</ocil:actions>26545 ··········</ocil:actions>
26564 ········</ocil:questionnaire>26546 ········</ocil:questionnaire>
26565 ········<ocil:questionnaire·id="ocil:ssg-service_psacct_enabled_ocil:questionnaire:1">26547 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1">
26566 ··········<ocil:title>Enable·Process·Accounting·(psacct)</ocil:title>26548 ··········<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title>
26567 ··········<ocil:actions>26549 ··········<ocil:actions>
26568 ············<ocil:test_action_ref>ocil:ssg-service_psacct_enabled_action:testaction:1</ocil:test_action_ref>26550 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
26569 ··········</ocil:actions>26551 ··········</ocil:actions>
26570 ········</ocil:questionnaire>26552 ········</ocil:questionnaire>
Max diff block lines reached; 237459/248793 bytes (95.44%) of diff not shown.
228 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ocil.xml
228 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ocil.xml
Ordering differences only
    
Offset 3, 1662 lines modifiedOffset 3, 1645 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
 10 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1">
 11 ······<ocil:title>Set·Lockout·Time·for·Failed·Password·Attempts</ocil:title>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1"> 
11 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1"> 
17 ······<ocil:title>Limit·Users'·SSH·Access</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1"> 
23 ······<ocil:title>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-package_telnet-server_removed_ocil:questionnaire:1"> 
29 ······<ocil:title>Uninstall·telnet-server·Package</ocil:title> 
30 ······<ocil:actions>12 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-package_telnet-server_removed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_unlock_time_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>14 ······</ocil:actions>
33 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minlen_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_lcredit_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Length</ocil:title>17 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Lowercase·Characters</ocil:title>
36 ······<ocil:actions>18 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minlen_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_lcredit_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>20 ······</ocil:actions>
39 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_unix_remember_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ocredit_ocil:questionnaire:1">
41 ······<ocil:title>Limit·Password·Reuse</ocil:title>23 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Special·Characters</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_remember_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ocredit_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"> 
47 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-require_emergency_target_auth_ocil:questionnaire:1">
 29 ······<ocil:title>Require·Authentication·for·Emergency·Systemd·Target</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-require_emergency_target_auth_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_deny_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-grub2_password_ocil:questionnaire:1">
53 ······<ocil:title>Lock·Accounts·After·Failed·Password·Attempts</ocil:title>35 ······<ocil:title>Set·Boot·Loader·Password·in·grub2</ocil:title>
54 ······<ocil:actions>36 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_deny_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-grub2_password_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>38 ······</ocil:actions>
57 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1">
59 ······<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title>41 ······<ocil:title>Configure·auditd·space_left·on·Low·Disk·Space</ocil:title>
60 ······<ocil:actions>42 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>44 ······</ocil:actions>
63 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-service_psacct_enabled_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1">
65 ······<ocil:title>Enable·Process·Accounting·(psacct)</ocil:title>47 ······<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title>
66 ······<ocil:actions>48 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-service_psacct_enabled_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>50 ······</ocil:actions>
69 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_etc_shadow_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sshd_print_last_log_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·There·Are·No·Accounts·With·Blank·or·Null·Passwords</ocil:title>53 ······<ocil:title>Enable·SSH·Print·Last·Log</ocil:title>
72 ······<ocil:actions>54 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-no_empty_passwords_etc_shadow_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sshd_print_last_log_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>56 ······</ocil:actions>
75 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-require_singleuser_auth_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-require_singleuser_auth_ocil:questionnaire:1">
77 ······<ocil:title>Require·Authentication·for·Single·User·Mode</ocil:title>59 ······<ocil:title>Require·Authentication·for·Single·User·Mode</ocil:title>
78 ······<ocil:actions>60 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-require_singleuser_auth_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-require_singleuser_auth_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>62 ······</ocil:actions>
81 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_ciphers_ocil:questionnaire:1">
83 ······<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title>65 ······<ocil:title>Use·Only·Strong·Ciphers</ocil:title>
84 ······<ocil:actions>66 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sshd_use_strong_ciphers_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>68 ······</ocil:actions>
87 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-service_dhcpd_disabled_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-service_sshd_enabled_ocil:questionnaire:1">
89 ······<ocil:title>Disable·DHCP·Service</ocil:title>71 ······<ocil:title>Enable·the·OpenSSH·Service</ocil:title>
90 ······<ocil:actions>72 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-service_dhcpd_disabled_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-service_sshd_enabled_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>74 ······</ocil:actions>
93 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">
95 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>77 ······<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>
96 ······<ocil:actions>78 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>80 ······</ocil:actions>
99 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ocredit_ocil:questionnaire:1"> 
101 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Special·Characters</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1">
 83 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title>
102 ······<ocil:actions>84 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ocredit_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>86 ······</ocil:actions>
105 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1"> 
107 ······<ocil:title>Verify·Permissions·on·group·File</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1">
 89 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title>
108 ······<ocil:actions>90 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_group_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>92 ······</ocil:actions>
111 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_passwordauth_ocil:questionnaire:1"> 
113 ······<ocil:title>Set·PAM''s·Password·Hashing·Algorithm·-·password-auth</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1">
 95 ······<ocil:title>Modify·the·System·Login·Banner</ocil:title>
114 ······<ocil:actions>96 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_passwordauth_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>98 ······</ocil:actions>
117 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1"> 
119 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1">
 101 ······<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title>
120 ······<ocil:actions>102 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>104 ······</ocil:actions>
Max diff block lines reached; 221487/232911 bytes (95.10%) of diff not shown.
9.12 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ds.xml
9.02 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:apple:macos:10.15">28 ······<cpe-dict:cpe-item·name="cpe:/o:apple:macos:10.15">
29 ········<cpe-dict:title·xml:lang="en-us">Apple·macOS·10.15</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Apple·macOS·10.15</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-macos1015-cpe-oval.xml">oval:ssg-installed_OS_is_macos1015:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-macos1015-cpe-oval.xml">oval:ssg-installed_OS_is_macos1015:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of40 configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 563, 15 lines modifiedOffset 563, 15 lines modified
563 ··············<xccdf-1.2:check-content-ref·href="ssg-macos1015-ocil.xml"·name="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"/>563 ··············<xccdf-1.2:check-content-ref·href="ssg-macos1015-ocil.xml"·name="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"/>
564 ············</xccdf-1.2:check>564 ············</xccdf-1.2:check>
565 ··········</xccdf-1.2:Rule>565 ··········</xccdf-1.2:Rule>
566 ········</xccdf-1.2:Group>566 ········</xccdf-1.2:Group>
567 ······</xccdf-1.2:Group>567 ······</xccdf-1.2:Group>
568 ····</xccdf-1.2:Benchmark>568 ····</xccdf-1.2:Benchmark>
569 ··</ds:component>569 ··</ds:component>
570 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-oval.xml"·timestamp="2025-02-28T20:08:00">570 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-oval.xml"·timestamp="2025-03-01T22:08:00">
571 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">571 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
572 ······<oval-def:generator>572 ······<oval-def:generator>
573 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>573 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
574 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>574 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
575 ········<oval:schema_version>5.11</oval:schema_version>575 ········<oval:schema_version>5.11</oval:schema_version>
576 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>576 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
577 ······</oval-def:generator>577 ······</oval-def:generator>
Offset 600, 74 lines modifiedOffset 600, 74 lines modified
600 ··········<ind:filepath>/etc/security/audit_control</ind:filepath>600 ··········<ind:filepath>/etc/security/audit_control</ind:filepath>
601 ··········<ind:pattern·operation="pattern·match">^policy:.*,ahlt.*$</ind:pattern>601 ··········<ind:pattern·operation="pattern·match">^policy:.*,ahlt.*$</ind:pattern>
602 ··········<ind:instance·datatype="int">1</ind:instance>602 ··········<ind:instance·datatype="int">1</ind:instance>
603 ········</ind:textfilecontent54_object>603 ········</ind:textfilecontent54_object>
604 ······</oval-def:objects>604 ······</oval-def:objects>
605 ····</oval-def:oval_definitions>605 ····</oval-def:oval_definitions>
606 ··</ds:component>606 ··</ds:component>
607 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-ocil.xml"·timestamp="2025-02-28T20:08:00">607 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-ocil.xml"·timestamp="2025-03-01T22:08:00">
608 ····<ocil:ocil>608 ····<ocil:ocil>
609 ······<ocil:generator>609 ······<ocil:generator>
610 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>610 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
611 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>611 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
612 ········<ocil:schema_version>2.0</ocil:schema_version>612 ········<ocil:schema_version>2.0</ocil:schema_version>
613 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>613 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
614 ······</ocil:generator>614 ······</ocil:generator>
615 ······<ocil:questionnaires>615 ······<ocil:questionnaires>
616 ········<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1"> 
617 ··········<ocil:title>Enable·audit·Service</ocil:title> 
618 ··········<ocil:actions> 
619 ············<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref> 
620 ··········</ocil:actions> 
621 ········</ocil:questionnaire> 
622 ········<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1">616 ········<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1">
623 ··········<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>617 ··········<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>
624 ··········<ocil:actions>618 ··········<ocil:actions>
625 ············<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref>619 ············<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref>
626 ··········</ocil:actions>620 ··········</ocil:actions>
627 ········</ocil:questionnaire>621 ········</ocil:questionnaire>
 622 ········<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1">
 623 ··········<ocil:title>Enable·audit·Service</ocil:title>
 624 ··········<ocil:actions>
 625 ············<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref>
 626 ··········</ocil:actions>
 627 ········</ocil:questionnaire>
628 ······</ocil:questionnaires>628 ······</ocil:questionnaires>
629 ······<ocil:test_actions>629 ······<ocil:test_actions>
630 ········<ocil:boolean_question_test_action·id="ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1"·question_ref="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">630 ········<ocil:boolean_question_test_action·id="ocil:ssg-audit_failure_halt_action:testaction:1"·question_ref="ocil:ssg-audit_failure_halt_question:question:1">
631 ··········<ocil:when_true>631 ··········<ocil:when_true>
632 ············<ocil:result>PASS</ocil:result>632 ············<ocil:result>PASS</ocil:result>
633 ··········</ocil:when_true>633 ··········</ocil:when_true>
634 ··········<ocil:when_false>634 ··········<ocil:when_false>
635 ············<ocil:result>FAIL</ocil:result>635 ············<ocil:result>FAIL</ocil:result>
636 ··········</ocil:when_false>636 ··········</ocil:when_false>
637 ········</ocil:boolean_question_test_action>637 ········</ocil:boolean_question_test_action>
638 ········<ocil:boolean_question_test_action·id="ocil:ssg-audit_failure_halt_action:testaction:1"·question_ref="ocil:ssg-audit_failure_halt_question:question:1">638 ········<ocil:boolean_question_test_action·id="ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1"·question_ref="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">
639 ··········<ocil:when_true>639 ··········<ocil:when_true>
640 ············<ocil:result>PASS</ocil:result>640 ············<ocil:result>PASS</ocil:result>
641 ··········</ocil:when_true>641 ··········</ocil:when_true>
642 ··········<ocil:when_false>642 ··········<ocil:when_false>
643 ············<ocil:result>FAIL</ocil:result>643 ············<ocil:result>FAIL</ocil:result>
644 ··········</ocil:when_false>644 ··········</ocil:when_false>
645 ········</ocil:boolean_question_test_action>645 ········</ocil:boolean_question_test_action>
646 ······</ocil:test_actions>646 ······</ocil:test_actions>
647 ······<ocil:questions>647 ······<ocil:questions>
 648 ········<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1">
 649 ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the
 650 following·command:
 651 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control
 652 The·output·should·contain·ahlt
 653 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text>
 654 ········</ocil:boolean_question>
648 ········<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">655 ········<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">
649 ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the656 ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the
650 following·command:657 following·command:
651 $·sudo·launchctl·list·com.apple.auditd658 $·sudo·launchctl·list·com.apple.auditd
652 The·output·should·return·process·information·for659 The·output·should·return·process·information·for
653 com.apple.auditd660 com.apple.auditd
654 ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text>661 ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text>
655 ········</ocil:boolean_question>662 ········</ocil:boolean_question>
656 ········<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1"> 
657 ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the 
658 following·command: 
659 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control 
660 The·output·should·contain·ahlt 
661 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text> 
662 ········</ocil:boolean_question> 
663 ······</ocil:questions>663 ······</ocil:questions>
664 ····</ocil:ocil>664 ····</ocil:ocil>
665 ··</ds:component>665 ··</ds:component>
666 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"·timestamp="2025-02-28T20:08:00">666 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"·timestamp="2025-03-01T22:08:00">
667 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">667 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
668 ······<oval-def:generator>668 ······<oval-def:generator>
669 ········<oval:product_name>build_cpe.py·from·SCAP·Security·Guide</oval:product_name>669 ········<oval:product_name>build_cpe.py·from·SCAP·Security·Guide</oval:product_name>
670 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>670 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
671 ········<oval:schema_version>5.11</oval:schema_version>671 ········<oval:schema_version>5.11</oval:schema_version>
672 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>672 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
673 ······</oval-def:generator>673 ······</oval-def:generator>
Max diff block lines reached; -1/9126 bytes (-0.01%) of diff not shown.
4.0 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ocil.xml
3.89 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ocil.xml
Ordering differences only
    
Offset 3, 56 lines modifiedOffset 3, 56 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1"> 
11 ······<ocil:title>Enable·audit·Service</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1">
17 ······<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>11 ······<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
 16 ····<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1">
 17 ······<ocil:title>Enable·audit·Service</ocil:title>
 18 ······<ocil:actions>
 19 ········<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref>
 20 ······</ocil:actions>
 21 ····</ocil:questionnaire>
22 ··</ocil:questionnaires>22 ··</ocil:questionnaires>
23 ··<ocil:test_actions>23 ··<ocil:test_actions>
24 ····<ocil:boolean_question_test_action·id="ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1"·question_ref="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">24 ····<ocil:boolean_question_test_action·id="ocil:ssg-audit_failure_halt_action:testaction:1"·question_ref="ocil:ssg-audit_failure_halt_question:question:1">
25 ······<ocil:when_true>25 ······<ocil:when_true>
26 ········<ocil:result>PASS</ocil:result>26 ········<ocil:result>PASS</ocil:result>
27 ······</ocil:when_true>27 ······</ocil:when_true>
28 ······<ocil:when_false>28 ······<ocil:when_false>
29 ········<ocil:result>FAIL</ocil:result>29 ········<ocil:result>FAIL</ocil:result>
30 ······</ocil:when_false>30 ······</ocil:when_false>
31 ····</ocil:boolean_question_test_action>31 ····</ocil:boolean_question_test_action>
32 ····<ocil:boolean_question_test_action·id="ocil:ssg-audit_failure_halt_action:testaction:1"·question_ref="ocil:ssg-audit_failure_halt_question:question:1">32 ····<ocil:boolean_question_test_action·id="ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1"·question_ref="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">
33 ······<ocil:when_true>33 ······<ocil:when_true>
34 ········<ocil:result>PASS</ocil:result>34 ········<ocil:result>PASS</ocil:result>
35 ······</ocil:when_true>35 ······</ocil:when_true>
36 ······<ocil:when_false>36 ······<ocil:when_false>
37 ········<ocil:result>FAIL</ocil:result>37 ········<ocil:result>FAIL</ocil:result>
38 ······</ocil:when_false>38 ······</ocil:when_false>
39 ····</ocil:boolean_question_test_action>39 ····</ocil:boolean_question_test_action>
40 ··</ocil:test_actions>40 ··</ocil:test_actions>
41 ··<ocil:questions>41 ··<ocil:questions>
 42 ····<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1">
 43 ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the
 44 following·command:
 45 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control
 46 The·output·should·contain·ahlt
 47 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text>
 48 ····</ocil:boolean_question>
42 ····<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">49 ····<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">
43 ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the50 ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the
44 following·command:51 following·command:
45 $·sudo·launchctl·list·com.apple.auditd52 $·sudo·launchctl·list·com.apple.auditd
46 The·output·should·return·process·information·for53 The·output·should·return·process·information·for
47 com.apple.auditd54 com.apple.auditd
48 ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text>55 ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text>
49 ····</ocil:boolean_question>56 ····</ocil:boolean_question>
50 ····<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1"> 
51 ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the 
52 following·command: 
53 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control 
54 The·output·should·contain·ahlt 
55 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text> 
56 ····</ocil:boolean_question> 
57 ··</ocil:questions>57 ··</ocil:questions>
58 </ocil:ocil>58 </ocil:ocil>
886 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds.xml
886 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.1">28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.1">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.10">32 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.10">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4.10</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4.10</cpe-dict:title>
Offset 111, 15 lines modifiedOffset 111, 15 lines modified
111 ······</cpe-dict:cpe-item>111 ······</cpe-dict:cpe-item>
112 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:openshift_container_platform_node:4">112 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:openshift_container_platform_node:4">
113 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4·Node</cpe-dict:title>113 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4·Node</cpe-dict:title>
114 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4_node:def:1</cpe-dict:check>114 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4_node:def:1</cpe-dict:check>
115 ······</cpe-dict:cpe-item>115 ······</cpe-dict:cpe-item>
116 ····</cpe-dict:cpe-list>116 ····</cpe-dict:cpe-list>
117 ··</ds:component>117 ··</ds:component>
118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-xccdf.xml"·timestamp="2025-02-28T20:08:00">118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-xccdf.xml"·timestamp="2025-03-01T22:08:00">
119 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OCP-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">119 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OCP-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
120 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>120 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
121 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container·Platform·4</xccdf-1.2:title>121 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container·Platform·4</xccdf-1.2:title>
122 ······<xccdf-1.2:description>122 ······<xccdf-1.2:description>
123 ········This·guide·presents·a·catalog·of·security-relevant123 ········This·guide·presents·a·catalog·of·security-relevant
124 configuration·settings·for·Red·Hat·OpenShift·Container·Platform·4.·It·is·a·rendering·of124 configuration·settings·for·Red·Hat·OpenShift·Container·Platform·4.·It·is·a·rendering·of
125 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)125 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 22582, 15 lines modifiedOffset 22582, 15 lines modified
22582 ··············<xccdf-1.2:check-content-ref·href="ssg-ocp4-ocil.xml"·name="ocil:ssg-file_permissions_worker_service_ocil:questionnaire:1"/>22582 ··············<xccdf-1.2:check-content-ref·href="ssg-ocp4-ocil.xml"·name="ocil:ssg-file_permissions_worker_service_ocil:questionnaire:1"/>
22583 ············</xccdf-1.2:check>22583 ············</xccdf-1.2:check>
22584 ··········</xccdf-1.2:Rule>22584 ··········</xccdf-1.2:Rule>
22585 ········</xccdf-1.2:Group>22585 ········</xccdf-1.2:Group>
22586 ······</xccdf-1.2:Group>22586 ······</xccdf-1.2:Group>
22587 ····</xccdf-1.2:Benchmark>22587 ····</xccdf-1.2:Benchmark>
22588 ··</ds:component>22588 ··</ds:component>
22589 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-oval.xml"·timestamp="2025-02-28T20:08:00">22589 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-oval.xml"·timestamp="2025-03-01T22:08:00">
22590 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">22590 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
22591 ······<oval-def:generator>22591 ······<oval-def:generator>
22592 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>22592 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
22593 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>22593 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
22594 ········<oval:schema_version>5.11</oval:schema_version>22594 ········<oval:schema_version>5.11</oval:schema_version>
22595 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>22595 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
22596 ······</oval-def:generator>22596 ······</oval-def:generator>
Offset 34382, 5557 lines modifiedOffset 34382, 5382 lines modified
34382 ············<oval-def:variable_component·var_ref="oval:ssg-ocp_data_root:var:1"/>34382 ············<oval-def:variable_component·var_ref="oval:ssg-ocp_data_root:var:1"/>
34383 ············<oval-def:literal_component>/apis/apps/v1/namespaces/openshift-ingress/deployments/router-default#aa685c2fe85cfde2ec878952fdd5e72b0824bdaccd1063efcfc29fea8137840c</oval-def:literal_component>34383 ············<oval-def:literal_component>/apis/apps/v1/namespaces/openshift-ingress/deployments/router-default#aa685c2fe85cfde2ec878952fdd5e72b0824bdaccd1063efcfc29fea8137840c</oval-def:literal_component>
34384 ··········</oval-def:concat>34384 ··········</oval-def:concat>
34385 ········</oval-def:local_variable>34385 ········</oval-def:local_variable>
34386 ······</oval-def:variables>34386 ······</oval-def:variables>
34387 ····</oval-def:oval_definitions>34387 ····</oval-def:oval_definitions>
34388 ··</ds:component>34388 ··</ds:component>
34389 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-ocil.xml"·timestamp="2025-02-28T20:08:00">34389 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-ocil.xml"·timestamp="2025-03-01T22:08:00">
34390 ····<ocil:ocil>34390 ····<ocil:ocil>
34391 ······<ocil:generator>34391 ······<ocil:generator>
34392 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>34392 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
34393 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>34393 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
34394 ········<ocil:schema_version>2.0</ocil:schema_version>34394 ········<ocil:schema_version>2.0</ocil:schema_version>
34395 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>34395 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
34396 ······</ocil:generator>34396 ······</ocil:generator>
34397 ······<ocil:questionnaires>34397 ······<ocil:questionnaires>
34398 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_ovs_pid_ocil:questionnaire:1">34398 ········<ocil:questionnaire·id="ocil:ssg-kube_descheduler_operator_exists_ocil:questionnaire:1">
34399 ··········<ocil:title>Verify·Permissions·on·the·Open·vSwitch·Process·ID·File</ocil:title>34399 ··········<ocil:title>Ensure·that·the·Kube·Descheduler·operator·is·deployed</ocil:title>
34400 ··········<ocil:actions>34400 ··········<ocil:actions>
34401 ············<ocil:test_action_ref>ocil:ssg-file_permissions_ovs_pid_action:testaction:1</ocil:test_action_ref>34401 ············<ocil:test_action_ref>ocil:ssg-kube_descheduler_operator_exists_action:testaction:1</ocil:test_action_ref>
34402 ··········</ocil:actions>34402 ··········</ocil:actions>
34403 ········</ocil:questionnaire>34403 ········</ocil:questionnaire>
34404 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_oauth_audit_ocil:questionnaire:1">34404 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_ocp_audit_ocil:questionnaire:1">
34405 ··········<ocil:title>OAuth·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>34405 ··········<ocil:title>OpenShift·Audit·Logs·Must·Have·Mode·0600</ocil:title>
34406 ··········<ocil:actions>34406 ··········<ocil:actions>
34407 ············<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_oauth_audit_action:testaction:1</ocil:test_action_ref>34407 ············<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_ocp_audit_action:testaction:1</ocil:test_action_ref>
34408 ··········</ocil:actions>34408 ··········</ocil:actions>
34409 ········</ocil:questionnaire>34409 ········</ocil:questionnaire>
34410 ········<ocil:questionnaire·id="ocil:ssg-master_taint_noschedule_ocil:questionnaire:1">34410 ········<ocil:questionnaire·id="ocil:ssg-api_server_token_auth_ocil:questionnaire:1">
34411 ··········<ocil:title>Verify·that·Control·Plane·Nodes·are·not·schedulable·for·workloads</ocil:title>34411 ··········<ocil:title>Disable·Token-based·Authentication</ocil:title>
34412 ··········<ocil:actions>34412 ··········<ocil:actions>
34413 ············<ocil:test_action_ref>ocil:ssg-master_taint_noschedule_action:testaction:1</ocil:test_action_ref>34413 ············<ocil:test_action_ref>ocil:ssg-api_server_token_auth_action:testaction:1</ocil:test_action_ref>
34414 ··········</ocil:actions>34414 ··········</ocil:actions>
34415 ········</ocil:questionnaire>34415 ········</ocil:questionnaire>
34416 ········<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_soft_imagefs_available_ocil:questionnaire:1"> 
34417 ··········<ocil:title>Ensure·Eviction·threshold·Settings·Are·Set·-·evictionSoft:·imagefs.available</ocil:title>34416 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_service_ocil:questionnaire:1">
 34417 ··········<ocil:title>Verify·Permissions·on·the·OpenShift·Node·Service·File</ocil:title>
34418 ··········<ocil:actions>34418 ··········<ocil:actions>
34419 ············<ocil:test_action_ref>ocil:ssg-kubelet_eviction_thresholds_set_soft_imagefs_available_action:testaction:1</ocil:test_action_ref>34419 ············<ocil:test_action_ref>ocil:ssg-file_permissions_worker_service_action:testaction:1</ocil:test_action_ref>
34420 ··········</ocil:actions>34420 ··········</ocil:actions>
34421 ········</ocil:questionnaire>34421 ········</ocil:questionnaire>
34422 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_pod_logs_ocil:questionnaire:1">34422 ········<ocil:questionnaire·id="ocil:ssg-file_owner_multus_conf_ocil:questionnaire:1">
34423 ··········<ocil:title>Kubernetes·Pod·Logs·Must·Be·Group·Owned·By·Root</ocil:title>34423 ··········<ocil:title>Verify·User·Who·Owns·The·OpenShift·Multus·Container·Network·Interface·Plugin·Files</ocil:title>
34424 ··········<ocil:actions>34424 ··········<ocil:actions>
34425 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_pod_logs_action:testaction:1</ocil:test_action_ref>34425 ············<ocil:test_action_ref>ocil:ssg-file_owner_multus_conf_action:testaction:1</ocil:test_action_ref>
34426 ··········</ocil:actions>34426 ··········</ocil:actions>
34427 ········</ocil:questionnaire>34427 ········</ocil:questionnaire>
34428 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_ovs_sys_id_conf_s390x_ocil:questionnaire:1">34428 ········<ocil:questionnaire·id="ocil:ssg-etcd_peer_auto_tls_ocil:questionnaire:1">
34429 ··········<ocil:title>Verify·Group·Who·Owns·The·Open·vSwitch·Persistent·System·ID</ocil:title>34429 ··········<ocil:title>Disable·etcd·Peer·Self-Signed·Certificates</ocil:title>
34430 ··········<ocil:actions>34430 ··········<ocil:actions>
34431 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_ovs_sys_id_conf_s390x_action:testaction:1</ocil:test_action_ref>34431 ············<ocil:test_action_ref>ocil:ssg-etcd_peer_auto_tls_action:testaction:1</ocil:test_action_ref>
34432 ··········</ocil:actions>34432 ··········</ocil:actions>
34433 ········</ocil:questionnaire>34433 ········</ocil:questionnaire>
34434 ········<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_hard_memory_available_ocil:questionnaire:1"> 
34435 ··········<ocil:title>Ensure·Eviction·threshold·Settings·Are·Set·-·evictionHard:·memory.available</ocil:title>34434 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etcd_data_dir_ocil:questionnaire:1">
 34435 ··········<ocil:title>Verify·User·Who·Owns·The·Etcd·Database·Directory</ocil:title>
34436 ··········<ocil:actions>34436 ··········<ocil:actions>
34437 ············<ocil:test_action_ref>ocil:ssg-kubelet_eviction_thresholds_set_hard_memory_available_action:testaction:1</ocil:test_action_ref>34437 ············<ocil:test_action_ref>ocil:ssg-file_owner_etcd_data_dir_action:testaction:1</ocil:test_action_ref>
34438 ··········</ocil:actions>34438 ··········</ocil:actions>
34439 ········</ocil:questionnaire>34439 ········</ocil:questionnaire>
34440 ········<ocil:questionnaire·id="ocil:ssg-general_backup_solution_installed_ocil:questionnaire:1">34440 ········<ocil:questionnaire·id="ocil:ssg-file_owner_ip_allocations_ocil:questionnaire:1">
34441 ··········<ocil:title>A·Backup·Solution·Has·To·Be·Installed</ocil:title>34441 ··········<ocil:title>Verify·User·Who·Owns·The·OpenShift·SDN·Container·Network·Interface·Plugin·IP·Address·Allocations</ocil:title>
34442 ··········<ocil:actions>34442 ··········<ocil:actions>
34443 ············<ocil:test_action_ref>ocil:ssg-general_backup_solution_installed_action:testaction:1</ocil:test_action_ref>34443 ············<ocil:test_action_ref>ocil:ssg-file_owner_ip_allocations_action:testaction:1</ocil:test_action_ref>
34444 ··········</ocil:actions>34444 ··········</ocil:actions>
34445 ········</ocil:questionnaire>34445 ········</ocil:questionnaire>
34446 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_ovn_cni_server_sock_ocil:questionnaire:1">34446 ········<ocil:questionnaire·id="ocil:ssg-etcd_check_cipher_suite_ocil:questionnaire:1">
34447 ··········<ocil:title>Verify·Group·Who·Owns·The·OVNKubernetes·Socket</ocil:title>34447 ··········<ocil:title>Ensure·ETCD·has·correct·cipher·suite</ocil:title>
34448 ··········<ocil:actions>34448 ··········<ocil:actions>
34449 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_ovn_cni_server_sock_action:testaction:1</ocil:test_action_ref>34449 ············<ocil:test_action_ref>ocil:ssg-etcd_check_cipher_suite_action:testaction:1</ocil:test_action_ref>
34450 ··········</ocil:actions>34450 ··········</ocil:actions>
34451 ········</ocil:questionnaire>34451 ········</ocil:questionnaire>
34452 ········<ocil:questionnaire·id="ocil:ssg-oauth_or_oauthclient_token_maxage_ocil:questionnaire:1">34452 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_kube_controller_manager_ocil:questionnaire:1">
34453 ··········<ocil:title>Configure·OAuth·tokens·to·expire·after·a·set·period·of·inactivity</ocil:title>34453 ··········<ocil:title>Verify·Permissions·on·the·Kubernetes·Controller·Manager·Pod·Specification·File</ocil:title>
34454 ··········<ocil:actions>34454 ··········<ocil:actions>
34455 ············<ocil:test_action_ref>ocil:ssg-oauth_or_oauthclient_token_maxage_action:testaction:1</ocil:test_action_ref>34455 ············<ocil:test_action_ref>ocil:ssg-file_permissions_kube_controller_manager_action:testaction:1</ocil:test_action_ref>
34456 ··········</ocil:actions>34456 ··········</ocil:actions>
34457 ········</ocil:questionnaire>34457 ········</ocil:questionnaire>
34458 ········<ocil:questionnaire·id="ocil:ssg-api_server_audit_log_maxbackup_ocil:questionnaire:1">34458 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_lib_etcd_ocil:questionnaire:1">
Max diff block lines reached; 894952/907488 bytes (98.62%) of diff not shown.
849 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ocil.xml
849 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ocil.xml
Ordering differences only
    
Offset 3, 5548 lines modifiedOffset 3, 5373 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ovs_pid_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-kube_descheduler_operator_exists_ocil:questionnaire:1">
11 ······<ocil:title>Verify·Permissions·on·the·Open·vSwitch·Process·ID·File</ocil:title>11 ······<ocil:title>Ensure·that·the·Kube·Descheduler·operator·is·deployed</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_ovs_pid_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-kube_descheduler_operator_exists_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_oauth_audit_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_ocp_audit_ocil:questionnaire:1">
17 ······<ocil:title>OAuth·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>17 ······<ocil:title>OpenShift·Audit·Logs·Must·Have·Mode·0600</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_oauth_audit_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_ocp_audit_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-master_taint_noschedule_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-api_server_token_auth_ocil:questionnaire:1">
23 ······<ocil:title>Verify·that·Control·Plane·Nodes·are·not·schedulable·for·workloads</ocil:title>23 ······<ocil:title>Disable·Token-based·Authentication</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-master_taint_noschedule_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-api_server_token_auth_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_soft_imagefs_available_ocil:questionnaire:1"> 
29 ······<ocil:title>Ensure·Eviction·threshold·Settings·Are·Set·-·evictionSoft:·imagefs.available</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_service_ocil:questionnaire:1">
 29 ······<ocil:title>Verify·Permissions·on·the·OpenShift·Node·Service·File</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kubelet_eviction_thresholds_set_soft_imagefs_available_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_worker_service_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_pod_logs_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_multus_conf_ocil:questionnaire:1">
35 ······<ocil:title>Kubernetes·Pod·Logs·Must·Be·Group·Owned·By·Root</ocil:title>35 ······<ocil:title>Verify·User·Who·Owns·The·OpenShift·Multus·Container·Network·Interface·Plugin·Files</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_pod_logs_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_owner_multus_conf_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_ovs_sys_id_conf_s390x_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-etcd_peer_auto_tls_ocil:questionnaire:1">
41 ······<ocil:title>Verify·Group·Who·Owns·The·Open·vSwitch·Persistent·System·ID</ocil:title>41 ······<ocil:title>Disable·etcd·Peer·Self-Signed·Certificates</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_ovs_sys_id_conf_s390x_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-etcd_peer_auto_tls_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_hard_memory_available_ocil:questionnaire:1"> 
47 ······<ocil:title>Ensure·Eviction·threshold·Settings·Are·Set·-·evictionHard:·memory.available</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etcd_data_dir_ocil:questionnaire:1">
 47 ······<ocil:title>Verify·User·Who·Owns·The·Etcd·Database·Directory</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-kubelet_eviction_thresholds_set_hard_memory_available_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_owner_etcd_data_dir_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-general_backup_solution_installed_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_owner_ip_allocations_ocil:questionnaire:1">
53 ······<ocil:title>A·Backup·Solution·Has·To·Be·Installed</ocil:title>53 ······<ocil:title>Verify·User·Who·Owns·The·OpenShift·SDN·Container·Network·Interface·Plugin·IP·Address·Allocations</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-general_backup_solution_installed_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_owner_ip_allocations_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_ovn_cni_server_sock_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-etcd_check_cipher_suite_ocil:questionnaire:1">
59 ······<ocil:title>Verify·Group·Who·Owns·The·OVNKubernetes·Socket</ocil:title>59 ······<ocil:title>Ensure·ETCD·has·correct·cipher·suite</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_ovn_cni_server_sock_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-etcd_check_cipher_suite_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-oauth_or_oauthclient_token_maxage_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_kube_controller_manager_ocil:questionnaire:1">
65 ······<ocil:title>Configure·OAuth·tokens·to·expire·after·a·set·period·of·inactivity</ocil:title>65 ······<ocil:title>Verify·Permissions·on·the·Kubernetes·Controller·Manager·Pod·Specification·File</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-oauth_or_oauthclient_token_maxage_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_kube_controller_manager_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-api_server_audit_log_maxbackup_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_lib_etcd_ocil:questionnaire:1">
71 ······<ocil:title>Configure·the·Kubernetes·API·Server·Maximum·Retained·Audit·Logs</ocil:title>71 ······<ocil:title>Verify·User·Who·Owns·The·OpenShift·etcd·Data·Directory</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-api_server_audit_log_maxbackup_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_lib_etcd_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-api_server_service_account_lookup_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-master_taint_noschedule_ocil:questionnaire:1">
77 ······<ocil:title>Ensure·that·the·service-account-lookup·argument·is·set·to·true</ocil:title>77 ······<ocil:title>Verify·that·Control·Plane·Nodes·are·not·schedulable·for·workloads</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-api_server_service_account_lookup_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-master_taint_noschedule_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ovn_db_files_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_kube_audit_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Permissions·on·the·OVNKubernetes·DB·files</ocil:title>83 ······<ocil:title>Kubernetes·Audit·Logs·Must·Have·Mode·0600</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_ovn_db_files_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_kube_audit_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-security_profiles_operator_exists_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-audit_profile_set_ocil:questionnaire:1">
89 ······<ocil:title>Make·sure·the·Security·Profiles·Operator·is·installed</ocil:title>89 ······<ocil:title>Ensure·that·the·cluster's·audit·profile·is·properly·set</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-security_profiles_operator_exists_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_profile_set_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-resource_requests_limits_in_deployment_ocil:questionnaire:1"> 
95 ······<ocil:title>Ensure·that·all·deployments·has·resource·limits</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-ingress_controller_certificate_ocil:questionnaire:1">
 95 ······<ocil:title>Ensure·that·the·default·Ingress·certificate·has·been·replaced</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-resource_requests_limits_in_deployment_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-ingress_controller_certificate_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_kube_scheduler_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-etcd_key_file_ocil:questionnaire:1">
101 ······<ocil:title>Verify·Group·Who·Owns·The·Kubernetes·Scheduler·Pod·Specification·File</ocil:title>101 ······<ocil:title>Ensure·That·The·etcd·Key·File·Is·Correctly·Set</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_kube_scheduler_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-etcd_key_file_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-cluster_version_operator_exists_ocil:questionnaire:1"> 
107 ······<ocil:title>Ensure·that·Cluster·Version·Operator·is·deployed</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-scc_limit_ipc_namespace_ocil:questionnaire:1">
 107 ······<ocil:title>Limit·Access·to·the·Host·IPC·Namespace</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-cluster_version_operator_exists_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-scc_limit_ipc_namespace_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-accounts_restrict_service_account_tokens_ocil:questionnaire:1"> 
113 ······<ocil:title>Restrict·Automounting·of·Service·Account·Tokens</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-resource_requests_limits_in_daemonset_ocil:questionnaire:1">
 113 ······<ocil:title>Ensure·that·all·daemonsets·has·resource·limits</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-accounts_restrict_service_account_tokens_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-resource_requests_limits_in_daemonset_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-rbac_wildcard_use_ocil:questionnaire:1"> 
119 ······<ocil:title>Minimize·Wildcard·Usage·in·Cluster·and·Local·Roles</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-scansetting_has_autoapplyremediations_ocil:questionnaire:1">
 119 ······<ocil:title>Enable·AutoApplyRemediation·for·at·least·One·ScanSetting</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-rbac_wildcard_use_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-scansetting_has_autoapplyremediations_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
Max diff block lines reached; 856241/869455 bytes (98.48%) of diff not shown.
1.81 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ds.xml
1.81 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:10">28 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:10">
29 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·10</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·10</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml">oval:ssg-installed_OS_is_ol10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml">oval:ssg-installed_OS_is_ol10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·10</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·10</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Oracle·Linux·10.·It·is·a·rendering·of40 configuration·settings·for·Oracle·Linux·10.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 194138, 15 lines modifiedOffset 194138, 15 lines modified
194138 ··············<xccdf-1.2:check-content-ref·href="ssg-ol10-ocil.xml"·name="ocil:ssg-audit_access_success_ocil:questionnaire:1"/>194138 ··············<xccdf-1.2:check-content-ref·href="ssg-ol10-ocil.xml"·name="ocil:ssg-audit_access_success_ocil:questionnaire:1"/>
194139 ············</xccdf-1.2:check>194139 ············</xccdf-1.2:check>
194140 ··········</xccdf-1.2:Rule>194140 ··········</xccdf-1.2:Rule>
194141 ········</xccdf-1.2:Group>194141 ········</xccdf-1.2:Group>
194142 ······</xccdf-1.2:Group>194142 ······</xccdf-1.2:Group>
194143 ····</xccdf-1.2:Benchmark>194143 ····</xccdf-1.2:Benchmark>
194144 ··</ds:component>194144 ··</ds:component>
194145 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-oval.xml"·timestamp="2025-02-28T20:08:00">194145 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-oval.xml"·timestamp="2025-03-01T22:08:00">
194146 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">194146 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
194147 ······<oval-def:generator>194147 ······<oval-def:generator>
194148 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>194148 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
194149 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>194149 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
194150 ········<oval:schema_version>5.11</oval:schema_version>194150 ········<oval:schema_version>5.11</oval:schema_version>
194151 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>194151 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
194152 ······</oval-def:generator>194152 ······</oval-def:generator>
Offset 237580, 6337 lines modifiedOffset 237580, 6337 lines modified
237580 ············</oval-def:arithmetic>237580 ············</oval-def:arithmetic>
237581 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>237581 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
237582 ··········</oval-def:arithmetic>237582 ··········</oval-def:arithmetic>
237583 ········</oval-def:local_variable>237583 ········</oval-def:local_variable>
237584 ······</oval-def:variables>237584 ······</oval-def:variables>
237585 ····</oval-def:oval_definitions>237585 ····</oval-def:oval_definitions>
237586 ··</ds:component>237586 ··</ds:component>
237587 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-ocil.xml"·timestamp="2025-02-28T20:08:00">237587 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-ocil.xml"·timestamp="2025-03-01T22:08:00">
237588 ····<ocil:ocil>237588 ····<ocil:ocil>
237589 ······<ocil:generator>237589 ······<ocil:generator>
237590 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>237590 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
237591 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>237591 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
237592 ········<ocil:schema_version>2.0</ocil:schema_version>237592 ········<ocil:schema_version>2.0</ocil:schema_version>
237593 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>237593 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
237594 ······</ocil:generator>237594 ······</ocil:generator>
237595 ······<ocil:questionnaires>237595 ······<ocil:questionnaires>
237596 ········<ocil:questionnaire·id="ocil:ssg-sshd_use_directory_configuration_ocil:questionnaire:1">237596 ········<ocil:questionnaire·id="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1">
237597 ··········<ocil:title>Distribute·the·SSH·Server·configuration·to·multiple·files·in·a·config·directory.</ocil:title>237597 ··········<ocil:title>Verify·Root·Has·A·Primary·GID·0</ocil:title>
237598 ··········<ocil:actions>237598 ··········<ocil:actions>
237599 ············<ocil:test_action_ref>ocil:ssg-sshd_use_directory_configuration_action:testaction:1</ocil:test_action_ref>237599 ············<ocil:test_action_ref>ocil:ssg-accounts_root_gid_zero_action:testaction:1</ocil:test_action_ref>
237600 ··········</ocil:actions>237600 ··········</ocil:actions>
237601 ········</ocil:questionnaire>237601 ········</ocil:questionnaire>
237602 ········<ocil:questionnaire·id="ocil:ssg-package_telnet_removed_ocil:questionnaire:1">237602 ········<ocil:questionnaire·id="ocil:ssg-chronyd_client_only_ocil:questionnaire:1">
237603 ··········<ocil:title>Remove·telnet·Clients</ocil:title>237603 ··········<ocil:title>Disable·chrony·daemon·from·acting·as·server</ocil:title>
237604 ··········<ocil:actions>237604 ··········<ocil:actions>
237605 ············<ocil:test_action_ref>ocil:ssg-package_telnet_removed_action:testaction:1</ocil:test_action_ref>237605 ············<ocil:test_action_ref>ocil:ssg-chronyd_client_only_action:testaction:1</ocil:test_action_ref>
237606 ··········</ocil:actions>237606 ··········</ocil:actions>
237607 ········</ocil:questionnaire>237607 ········</ocil:questionnaire>
237608 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_stig_ocil:questionnaire:1"> 
237609 ··········<ocil:title>System·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>237608 ········<ocil:questionnaire·id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1">
 237609 ··········<ocil:title>Ensure·gnutls-utils·is·installed</ocil:title>
237610 ··········<ocil:actions>237610 ··········<ocil:actions>
237611 ············<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_stig_action:testaction:1</ocil:test_action_ref>237611 ············<ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref>
237612 ··········</ocil:actions>237612 ··········</ocil:actions>
237613 ········</ocil:questionnaire>237613 ········</ocil:questionnaire>
237614 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1">237614 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_strict_module_rwx_ocil:questionnaire:1">
237615 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lsetxattr</ocil:title>237615 ··········<ocil:title>Make·the·module·text·and·rodata·read-only</ocil:title>
237616 ··········<ocil:actions>237616 ··········<ocil:actions>
237617 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>237617 ············<ocil:test_action_ref>ocil:ssg-kernel_config_strict_module_rwx_action:testaction:1</ocil:test_action_ref>
237618 ··········</ocil:actions>237618 ··········</ocil:actions>
237619 ········</ocil:questionnaire>237619 ········</ocil:questionnaire>
237620 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1"> 
237621 ··········<ocil:title>Ensure·All·Files·Are·Owned·by·a·Group</ocil:title>237620 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1">
 237621 ··········<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title>
237622 ··········<ocil:actions>237622 ··········<ocil:actions>
237623 ············<ocil:test_action_ref>ocil:ssg-file_permissions_ungroupowned_action:testaction:1</ocil:test_action_ref>237623 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>
237624 ··········</ocil:actions>237624 ··········</ocil:actions>
237625 ········</ocil:questionnaire>237625 ········</ocil:questionnaire>
237626 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1">237626 ········<ocil:questionnaire·id="ocil:ssg-set_firewalld_default_zone_ocil:questionnaire:1">
237627 ··········<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title>237627 ··········<ocil:title>Set·Default·firewalld·Zone·for·Incoming·Packets</ocil:title>
237628 ··········<ocil:actions>237628 ··········<ocil:actions>
237629 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref>237629 ············<ocil:test_action_ref>ocil:ssg-set_firewalld_default_zone_action:testaction:1</ocil:test_action_ref>
237630 ··········</ocil:actions>237630 ··········</ocil:actions>
237631 ········</ocil:questionnaire>237631 ········</ocil:questionnaire>
237632 ········<ocil:questionnaire·id="ocil:ssg-aide_use_fips_hashes_ocil:questionnaire:1">237632 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1">
237633 ··········<ocil:title>Configure·AIDE·to·Use·FIPS·140-2·for·Validating·Hashes</ocil:title>237633 ··········<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title>
237634 ··········<ocil:actions>237634 ··········<ocil:actions>
237635 ············<ocil:test_action_ref>ocil:ssg-aide_use_fips_hashes_action:testaction:1</ocil:test_action_ref>237635 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
237636 ··········</ocil:actions>237636 ··········</ocil:actions>
237637 ········</ocil:questionnaire>237637 ········</ocil:questionnaire>
237638 ········<ocil:questionnaire·id="ocil:ssg-mount_option_nodev_removable_partitions_ocil:questionnaire:1"> 
237639 ··········<ocil:title>Add·nodev·Option·to·Removable·Media·Partitions</ocil:title>237638 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1">
 237639 ··········<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title>
237640 ··········<ocil:actions>237640 ··········<ocil:actions>
237641 ············<ocil:test_action_ref>ocil:ssg-mount_option_nodev_removable_partitions_action:testaction:1</ocil:test_action_ref>237641 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref>
237642 ··········</ocil:actions>237642 ··········</ocil:actions>
237643 ········</ocil:questionnaire>237643 ········</ocil:questionnaire>
237644 ········<ocil:questionnaire·id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1">237644 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1">
237645 ··········<ocil:title>Deactivate·Wireless·Network·Interfaces</ocil:title>237645 ··········<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title>
237646 ··········<ocil:actions>237646 ··········<ocil:actions>
237647 ············<ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref>237647 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
237648 ··········</ocil:actions>237648 ··········</ocil:actions>
237649 ········</ocil:questionnaire>237649 ········</ocil:questionnaire>
237650 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_ocil:questionnaire:1"> 
237651 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·unix_chkpwd</ocil:title>237650 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">
 237651 ··········<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>
237652 ··········<ocil:actions>237652 ··········<ocil:actions>
237653 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_action:testaction:1</ocil:test_action_ref>237653 ············<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>
237654 ··········</ocil:actions>237654 ··········</ocil:actions>
237655 ········</ocil:questionnaire>237655 ········</ocil:questionnaire>
237656 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_system_shutdown_ocil:questionnaire:1">237656 ········<ocil:questionnaire·id="ocil:ssg-networkmanager_dns_mode_ocil:questionnaire:1">
237657 ··········<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>237657 ··········<ocil:title>NetworkManager·DNS·Mode·Must·Be·Must·Configured</ocil:title>
237658 ··········<ocil:actions>237658 ··········<ocil:actions>
237659 ············<ocil:test_action_ref>ocil:ssg-audit_rules_system_shutdown_action:testaction:1</ocil:test_action_ref>237659 ············<ocil:test_action_ref>ocil:ssg-networkmanager_dns_mode_action:testaction:1</ocil:test_action_ref>
237660 ··········</ocil:actions>237660 ··········</ocil:actions>
237661 ········</ocil:questionnaire>237661 ········</ocil:questionnaire>
237662 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1"> 
Max diff block lines reached; 1888034/1900229 bytes (99.36%) of diff not shown.
1.74 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ocil.xml
1.73 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ocil.xml
Ordering differences only
    
Offset 3, 6328 lines modifiedOffset 3, 6328 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_directory_configuration_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1">
11 ······<ocil:title>Distribute·the·SSH·Server·configuration·to·multiple·files·in·a·config·directory.</ocil:title>11 ······<ocil:title>Verify·Root·Has·A·Primary·GID·0</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-sshd_use_directory_configuration_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-accounts_root_gid_zero_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-package_telnet_removed_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-chronyd_client_only_ocil:questionnaire:1">
17 ······<ocil:title>Remove·telnet·Clients</ocil:title>17 ······<ocil:title>Disable·chrony·daemon·from·acting·as·server</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_telnet_removed_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-chronyd_client_only_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_stig_ocil:questionnaire:1"> 
23 ······<ocil:title>System·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1">
 23 ······<ocil:title>Ensure·gnutls-utils·is·installed</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_stig_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1"> 
29 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lsetxattr</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_strict_module_rwx_ocil:questionnaire:1">
 29 ······<ocil:title>Make·the·module·text·and·rodata·read-only</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_strict_module_rwx_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1"> 
35 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·Group</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1">
 35 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_ungroupowned_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-set_firewalld_default_zone_ocil:questionnaire:1">
41 ······<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title>41 ······<ocil:title>Set·Default·firewalld·Zone·for·Incoming·Packets</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-set_firewalld_default_zone_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-aide_use_fips_hashes_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1">
47 ······<ocil:title>Configure·AIDE·to·Use·FIPS·140-2·for·Validating·Hashes</ocil:title>47 ······<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-aide_use_fips_hashes_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-mount_option_nodev_removable_partitions_ocil:questionnaire:1"> 
53 ······<ocil:title>Add·nodev·Option·to·Removable·Media·Partitions</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1">
 53 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-mount_option_nodev_removable_partitions_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1">
59 ······<ocil:title>Deactivate·Wireless·Network·Interfaces</ocil:title>59 ······<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_ocil:questionnaire:1"> 
65 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·unix_chkpwd</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">
 65 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_system_shutdown_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-networkmanager_dns_mode_ocil:questionnaire:1">
71 ······<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>71 ······<ocil:title>NetworkManager·DNS·Mode·Must·Be·Must·Configured</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_system_shutdown_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-networkmanager_dns_mode_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1"> 
77 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-service_sssd_enabled_ocil:questionnaire:1">
 77 ······<ocil:title>Enable·the·SSSD·Service</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-service_sssd_enabled_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_session_idle_user_locks_ocil:questionnaire:1"> 
83 ······<ocil:title>Ensure·Users·Cannot·Change·GNOME3·Session·Idle·Settings</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-service_kdump_disabled_ocil:questionnaire:1">
 83 ······<ocil:title>Disable·KDump·Kernel·Crash·Analyzer·(kdump)</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_session_idle_user_locks_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-service_kdump_disabled_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_chsh_ocil:questionnaire:1">
89 ······<ocil:title>Verify·Permissions·on·/etc/audit/rules.d/*.rules</ocil:title>89 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·chsh</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_audit_rulesd_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_chsh_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_suid_ocil:questionnaire:1"> 
95 ······<ocil:title>Ensure·All·SUID·Executables·Are·Authorized</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_ocil:questionnaire:1">
 95 ······<ocil:title>Limit·Password·Reuse:·password-auth</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_suid_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_yama_ptrace_scope_ocil:questionnaire:1"> 
101 ······<ocil:title>Restrict·usage·of·ptrace·to·descendant·processes</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_noexec_ocil:questionnaire:1">
 101 ······<ocil:title>Add·noexec·Option·to·/boot</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_yama_ptrace_scope_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_noexec_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_daily_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_sudoers_ocil:questionnaire:1">
107 ······<ocil:title>Verify·Group·Who·Owns·cron.daily</ocil:title>107 ······<ocil:title>Verify·Permissions·On·/etc/sudoers·File</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_daily_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_sudoers_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sebool_kerberos_enabled_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-sudoers_explicit_command_args_ocil:questionnaire:1">
113 ······<ocil:title>Enable·the·kerberos_enabled·SELinux·Boolean</ocil:title>113 ······<ocil:title>Explicit·arguments·in·sudo·specifications</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sebool_kerberos_enabled_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sudoers_explicit_command_args_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·gpgcheck·Enabled·In·Main·dnf·Configuration</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-directory_groupowner_etc_selinux_ocil:questionnaire:1">
 119 ······<ocil:title>Verify·Group·Who·Owns·/etc/selinux·Directory</ocil:title>
Max diff block lines reached; 1806750/1819121 bytes (99.32%) of diff not shown.
2.19 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds.xml
2.19 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol7.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol7.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol7.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol7.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:7">30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:7">
31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·7</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·7</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml">oval:ssg-installed_OS_is_ol7:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml">oval:ssg-installed_OS_is_ol7:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-7"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-7"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·7</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·7</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Oracle·Linux·7.·It·is·a·rendering·of42 configuration·settings·for·Oracle·Linux·7.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 237865, 15 lines modifiedOffset 237865, 15 lines modified
237865 ··············<xccdf-1.2:check-content-ref·href="ssg-ol7-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>237865 ··············<xccdf-1.2:check-content-ref·href="ssg-ol7-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
237866 ············</xccdf-1.2:check>237866 ············</xccdf-1.2:check>
237867 ··········</xccdf-1.2:Rule>237867 ··········</xccdf-1.2:Rule>
237868 ········</xccdf-1.2:Group>237868 ········</xccdf-1.2:Group>
237869 ······</xccdf-1.2:Group>237869 ······</xccdf-1.2:Group>
237870 ····</xccdf-1.2:Benchmark>237870 ····</xccdf-1.2:Benchmark>
237871 ··</ds:component>237871 ··</ds:component>
237872 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-oval.xml"·timestamp="2025-02-28T20:08:00">237872 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-oval.xml"·timestamp="2025-03-01T22:08:00">
237873 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">237873 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
237874 ······<oval-def:generator>237874 ······<oval-def:generator>
237875 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>237875 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
237876 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>237876 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
237877 ········<oval:schema_version>5.11</oval:schema_version>237877 ········<oval:schema_version>5.11</oval:schema_version>
237878 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>237878 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
237879 ······</oval-def:generator>237879 ······</oval-def:generator>
Offset 286201, 10951 lines modifiedOffset 286201, 10951 lines modified
286201 ············</oval-def:arithmetic>286201 ············</oval-def:arithmetic>
286202 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>286202 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
286203 ··········</oval-def:arithmetic>286203 ··········</oval-def:arithmetic>
286204 ········</oval-def:local_variable>286204 ········</oval-def:local_variable>
286205 ······</oval-def:variables>286205 ······</oval-def:variables>
286206 ····</oval-def:oval_definitions>286206 ····</oval-def:oval_definitions>
286207 ··</ds:component>286207 ··</ds:component>
286208 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-ocil.xml"·timestamp="2025-02-28T20:08:00">286208 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-ocil.xml"·timestamp="2025-03-01T22:08:00">
286209 ····<ocil:ocil>286209 ····<ocil:ocil>
286210 ······<ocil:generator>286210 ······<ocil:generator>
286211 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>286211 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
286212 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>286212 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
286213 ········<ocil:schema_version>2.0</ocil:schema_version>286213 ········<ocil:schema_version>2.0</ocil:schema_version>
286214 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>286214 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
286215 ······</ocil:generator>286215 ······</ocil:generator>
286216 ······<ocil:questionnaires>286216 ······<ocil:questionnaires>
286217 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fsetxattr_ocil:questionnaire:1">286217 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_idle_activation_locked_ocil:questionnaire:1">
 286218 ··········<ocil:title>Ensure·Users·Cannot·Change·GNOME3·Screensaver·Idle·Activation</ocil:title>
286218 ··········<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fsetxattr</ocil:title> 
286219 ··········<ocil:actions> 
286220 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fsetxattr_action:testaction:1</ocil:test_action_ref> 
286221 ··········</ocil:actions> 
286222 ········</ocil:questionnaire> 
286223 ········<ocil:questionnaire·id="ocil:ssg-package_policycoreutils_installed_ocil:questionnaire:1"> 
286224 ··········<ocil:title>Install·policycoreutils·Package</ocil:title> 
286225 ··········<ocil:actions>286219 ··········<ocil:actions>
286226 ············<ocil:test_action_ref>ocil:ssg-package_policycoreutils_installed_action:testaction:1</ocil:test_action_ref>286220 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_idle_activation_locked_action:testaction:1</ocil:test_action_ref>
286227 ··········</ocil:actions>286221 ··········</ocil:actions>
286228 ········</ocil:questionnaire>286222 ········</ocil:questionnaire>
286229 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1"> 
286230 ··········<ocil:title>Unmap·kernel·when·running·in·userspace·(aka·KAISER)</ocil:title>286223 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1">
 286224 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Different·Categories</ocil:title>
286231 ··········<ocil:actions>286225 ··········<ocil:actions>
286232 ············<ocil:test_action_ref>ocil:ssg-kernel_config_unmap_kernel_at_el0_action:testaction:1</ocil:test_action_ref>286226 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minclass_action:testaction:1</ocil:test_action_ref>
286233 ··········</ocil:actions>286227 ··········</ocil:actions>
286234 ········</ocil:questionnaire>286228 ········</ocil:questionnaire>
286235 ········<ocil:questionnaire·id="ocil:ssg-rpm_verify_ownership_ocil:questionnaire:1"> 
286236 ··········<ocil:title>Verify·and·Correct·Ownership·with·RPM</ocil:title>286229 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_lsetxattr_ocil:questionnaire:1">
 286230 ··········<ocil:title>Record·Successful·Permission·Changes·to·Files·-·lsetxattr</ocil:title>
286237 ··········<ocil:actions>286231 ··········<ocil:actions>
286238 ············<ocil:test_action_ref>ocil:ssg-rpm_verify_ownership_action:testaction:1</ocil:test_action_ref>286232 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>
286239 ··········</ocil:actions>286233 ··········</ocil:actions>
286240 ········</ocil:questionnaire>286234 ········</ocil:questionnaire>
286241 ········<ocil:questionnaire·id="ocil:ssg-ensure_logrotate_activated_ocil:questionnaire:1">286235 ········<ocil:questionnaire·id="ocil:ssg-mount_option_boot_nodev_ocil:questionnaire:1">
286242 ··········<ocil:title>Ensure·Logrotate·Runs·Periodically</ocil:title>286236 ··········<ocil:title>Add·nodev·Option·to·/boot</ocil:title>
286243 ··········<ocil:actions>286237 ··········<ocil:actions>
286244 ············<ocil:test_action_ref>ocil:ssg-ensure_logrotate_activated_action:testaction:1</ocil:test_action_ref>286238 ············<ocil:test_action_ref>ocil:ssg-mount_option_boot_nodev_action:testaction:1</ocil:test_action_ref>
286245 ··········</ocil:actions>286239 ··········</ocil:actions>
286246 ········</ocil:questionnaire>286240 ········</ocil:questionnaire>
286247 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1">286241 ········<ocil:questionnaire·id="ocil:ssg-grub2_vsyscall_argument_ocil:questionnaire:1">
286248 ··········<ocil:title>Enable·SSH·Warning·Banner</ocil:title>286242 ··········<ocil:title>Disable·vsyscalls</ocil:title>
286249 ··········<ocil:actions>286243 ··········<ocil:actions>
286250 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref>286244 ············<ocil:test_action_ref>ocil:ssg-grub2_vsyscall_argument_action:testaction:1</ocil:test_action_ref>
286251 ··········</ocil:actions>286245 ··········</ocil:actions>
286252 ········</ocil:questionnaire>286246 ········</ocil:questionnaire>
286253 ········<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1"> 
286254 ··········<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>286247 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_ocil:questionnaire:1">
 286248 ··········<ocil:title>Disable·Kernel·Parameter·for·IPv6·Forwarding</ocil:title>
286255 ··········<ocil:actions>286249 ··········<ocil:actions>
286256 ············<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>286250 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_action:testaction:1</ocil:test_action_ref>
286257 ··········</ocil:actions>286251 ··········</ocil:actions>
286258 ········</ocil:questionnaire>286252 ········</ocil:questionnaire>
286259 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_acpi_custom_method_ocil:questionnaire:1">286253 ········<ocil:questionnaire·id="ocil:ssg-package_uuidd_installed_ocil:questionnaire:1">
286260 ··········<ocil:title>Do·not·allow·ACPI·methods·to·be·inserted/replaced·at·run·time</ocil:title>286254 ··········<ocil:title>Package·uuidd·Installed</ocil:title>
286261 ··········<ocil:actions>286255 ··········<ocil:actions>
286262 ············<ocil:test_action_ref>ocil:ssg-kernel_config_acpi_custom_method_action:testaction:1</ocil:test_action_ref>286256 ············<ocil:test_action_ref>ocil:ssg-package_uuidd_installed_action:testaction:1</ocil:test_action_ref>
286263 ··········</ocil:actions>286257 ··········</ocil:actions>
286264 ········</ocil:questionnaire>286258 ········</ocil:questionnaire>
286265 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1"> 
286266 ··········<ocil:title>System·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>286259 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_open_ocil:questionnaire:1">
 286260 ··········<ocil:title>Record·Successful·Access·Attempts·to·Files·-·open</ocil:title>
286267 ··········<ocil:actions>286261 ··········<ocil:actions>
286268 ············<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>286262 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_open_action:testaction:1</ocil:test_action_ref>
286269 ··········</ocil:actions>286263 ··········</ocil:actions>
286270 ········</ocil:questionnaire>286264 ········</ocil:questionnaire>
286271 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rmdir_ocil:questionnaire:1">286265 ········<ocil:questionnaire·id="ocil:ssg-grub2_enable_fips_mode_ocil:questionnaire:1">
286272 ··········<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rmdir</ocil:title>286266 ··········<ocil:title>Enable·FIPS·Mode·in·GRUB2</ocil:title>
286273 ··········<ocil:actions>286267 ··········<ocil:actions>
286274 ············<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rmdir_action:testaction:1</ocil:test_action_ref>286268 ············<ocil:test_action_ref>ocil:ssg-grub2_enable_fips_mode_action:testaction:1</ocil:test_action_ref>
286275 ··········</ocil:actions>286269 ··········</ocil:actions>
286276 ········</ocil:questionnaire>286270 ········</ocil:questionnaire>
286277 ········<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_pub_key_ocil:questionnaire:1">286271 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_sshd_config_ocil:questionnaire:1">
286278 ··········<ocil:title>Verify·Group·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>286272 ··········<ocil:title>Verify·Group·Who·Owns·SSH·Server·config·file</ocil:title>
286279 ··········<ocil:actions>286273 ··········<ocil:actions>
286280 ············<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>286274 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_sshd_config_action:testaction:1</ocil:test_action_ref>
286281 ··········</ocil:actions>286275 ··········</ocil:actions>
286282 ········</ocil:questionnaire>286276 ········</ocil:questionnaire>
Max diff block lines reached; 2282183/2294156 bytes (99.48%) of diff not shown.
2.1 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ocil.xml
2.1 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ocil.xml
Ordering differences only
    
Offset 3, 10942 lines modifiedOffset 3, 10942 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fsetxattr_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_idle_activation_locked_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·Users·Cannot·Change·GNOME3·Screensaver·Idle·Activation</ocil:title>
11 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fsetxattr</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fsetxattr_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-package_policycoreutils_installed_ocil:questionnaire:1"> 
17 ······<ocil:title>Install·policycoreutils·Package</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_policycoreutils_installed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_idle_activation_locked_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1"> 
23 ······<ocil:title>Unmap·kernel·when·running·in·userspace·(aka·KAISER)</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1">
 17 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Different·Categories</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_unmap_kernel_at_el0_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minclass_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_ownership_ocil:questionnaire:1"> 
29 ······<ocil:title>Verify·and·Correct·Ownership·with·RPM</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_lsetxattr_ocil:questionnaire:1">
 23 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·lsetxattr</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-rpm_verify_ownership_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-ensure_logrotate_activated_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_nodev_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·Logrotate·Runs·Periodically</ocil:title>29 ······<ocil:title>Add·nodev·Option·to·/boot</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-ensure_logrotate_activated_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_nodev_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-grub2_vsyscall_argument_ocil:questionnaire:1">
41 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>35 ······<ocil:title>Disable·vsyscalls</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-grub2_vsyscall_argument_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1"> 
47 ······<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_ocil:questionnaire:1">
 41 ······<ocil:title>Disable·Kernel·Parameter·for·IPv6·Forwarding</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_acpi_custom_method_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-package_uuidd_installed_ocil:questionnaire:1">
53 ······<ocil:title>Do·not·allow·ACPI·methods·to·be·inserted/replaced·at·run·time</ocil:title>47 ······<ocil:title>Package·uuidd·Installed</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-kernel_config_acpi_custom_method_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-package_uuidd_installed_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1"> 
59 ······<ocil:title>System·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_open_ocil:questionnaire:1">
 53 ······<ocil:title>Record·Successful·Access·Attempts·to·Files·-·open</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_open_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rmdir_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_fips_mode_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rmdir</ocil:title>59 ······<ocil:title>Enable·FIPS·Mode·in·GRUB2</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rmdir_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-grub2_enable_fips_mode_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_pub_key_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_sshd_config_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Group·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>65 ······<ocil:title>Verify·Group·Who·Owns·SSH·Server·config·file</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_sshd_config_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-mount_option_nosuid_remote_filesystems_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_ignore_dot_ocil:questionnaire:1">
77 ······<ocil:title>Mount·Remote·Filesystems·with·nosuid</ocil:title>71 ······<ocil:title>Ensure·sudo·Ignores·Commands·In·Current·Dir·-·sudo·ignore_dot</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-mount_option_nosuid_remote_filesystems_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sudo_add_ignore_dot_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-aide_verify_ext_attributes_ocil:questionnaire:1"> 
83 ······<ocil:title>Configure·AIDE·to·Verify·Extended·Attributes</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1">
 77 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-aide_verify_ext_attributes_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-snmpd_not_default_password_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_efi_user_cfg_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·Default·SNMP·Password·Is·Not·Used</ocil:title>83 ······<ocil:title>Verify·/boot/efi/EFI/redhat/user.cfg·Group·Ownership</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-snmpd_not_default_password_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_efi_user_cfg_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_noauto_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-security_patches_up_to_date_ocil:questionnaire:1">
95 ······<ocil:title>Add·noauto·Option·to·/boot</ocil:title>89 ······<ocil:title>Ensure·Software·Patches·Installed</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_noauto_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-security_patches_up_to_date_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_library_dirs_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-ldap_client_start_tls_ocil:questionnaire:1">
101 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Ownership</ocil:title>95 ······<ocil:title>Configure·LDAP·Client·to·Use·TLS·For·All·Transactions</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-ldap_client_start_tls_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_owner_sshd_config_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1">
107 ······<ocil:title>Verify·Owner·on·SSH·Server·config·file</ocil:title>101 ······<ocil:title>Verify·User·Who·Owns·Backup·passwd·File</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_owner_sshd_config_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-aide_periodic_cron_checking_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-dconf_db_up_to_date_ocil:questionnaire:1">
113 ······<ocil:title>Configure·Periodic·Execution·of·AIDE</ocil:title>107 ······<ocil:title>Make·sure·that·the·dconf·databases·are·up-to-date·with·regards·to·respective·keyfiles</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-aide_periodic_cron_checking_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-dconf_db_up_to_date_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1"> 
119 ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_lchown_ocil:questionnaire:1">
 113 ······<ocil:title>Record·Unsuccessful·Ownership·Changes·to·Files·-·lchown</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_lchown_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
Max diff block lines reached; 2184521/2196832 bytes (99.44%) of diff not shown.
2.59 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds.xml
2.59 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol8.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol8.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol8.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol8.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:8">30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:8">
31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·8</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·8</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml">oval:ssg-installed_OS_is_ol8:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml">oval:ssg-installed_OS_is_ol8:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·8</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·8</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Oracle·Linux·8.·It·is·a·rendering·of42 configuration·settings·for·Oracle·Linux·8.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 386, 25 lines modifiedOffset 386, 25 lines modified
386 ··········</cpe-lang:logical-test>386 ··········</cpe-lang:logical-test>
387 ········</cpe-lang:platform>387 ········</cpe-lang:platform>
388 ········<cpe-lang:platform·id="package_bash">388 ········<cpe-lang:platform·id="package_bash">
389 ··········<cpe-lang:logical-test·operator="AND"·negate="false">389 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
390 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>390 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
391 ··········</cpe-lang:logical-test>391 ··········</cpe-lang:logical-test>
392 ········</cpe-lang:platform>392 ········</cpe-lang:platform>
393 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
394 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
395 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
396 ··········</cpe-lang:logical-test> 
397 ········</cpe-lang:platform> 
398 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">393 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
399 ··········<cpe-lang:logical-test·operator="AND"·negate="false">394 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
400 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>395 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
401 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>396 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
402 ··········</cpe-lang:logical-test>397 ··········</cpe-lang:logical-test>
403 ········</cpe-lang:platform>398 ········</cpe-lang:platform>
 399 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 400 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 401 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 402 ··········</cpe-lang:logical-test>
 403 ········</cpe-lang:platform>
404 ········<cpe-lang:platform·id="not_s390x_arch">404 ········<cpe-lang:platform·id="not_s390x_arch">
405 ··········<cpe-lang:logical-test·operator="AND"·negate="false">405 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
406 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>406 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
407 ··········</cpe-lang:logical-test>407 ··········</cpe-lang:logical-test>
408 ········</cpe-lang:platform>408 ········</cpe-lang:platform>
409 ········<cpe-lang:platform·id="package_tmux">409 ········<cpe-lang:platform·id="package_tmux">
410 ··········<cpe-lang:logical-test·operator="AND"·negate="false">410 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 264643, 15 lines modifiedOffset 264643, 15 lines modified
264643 ··············<xccdf-1.2:check-content-ref·href="ssg-ol8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>264643 ··············<xccdf-1.2:check-content-ref·href="ssg-ol8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
264644 ············</xccdf-1.2:check>264644 ············</xccdf-1.2:check>
264645 ··········</xccdf-1.2:Rule>264645 ··········</xccdf-1.2:Rule>
264646 ········</xccdf-1.2:Group>264646 ········</xccdf-1.2:Group>
264647 ······</xccdf-1.2:Group>264647 ······</xccdf-1.2:Group>
264648 ····</xccdf-1.2:Benchmark>264648 ····</xccdf-1.2:Benchmark>
264649 ··</ds:component>264649 ··</ds:component>
264650 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-oval.xml"·timestamp="2025-02-28T20:08:00">264650 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-oval.xml"·timestamp="2025-03-01T22:08:00">
264651 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">264651 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
264652 ······<oval-def:generator>264652 ······<oval-def:generator>
264653 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>264653 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
264654 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>264654 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
264655 ········<oval:schema_version>5.11</oval:schema_version>264655 ········<oval:schema_version>5.11</oval:schema_version>
264656 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>264656 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
264657 ······</oval-def:generator>264657 ······</oval-def:generator>
Offset 321125, 10521 lines modifiedOffset 321125, 10521 lines modified
321125 ············</oval-def:arithmetic>321125 ············</oval-def:arithmetic>
321126 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>321126 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
321127 ··········</oval-def:arithmetic>321127 ··········</oval-def:arithmetic>
321128 ········</oval-def:local_variable>321128 ········</oval-def:local_variable>
321129 ······</oval-def:variables>321129 ······</oval-def:variables>
321130 ····</oval-def:oval_definitions>321130 ····</oval-def:oval_definitions>
321131 ··</ds:component>321131 ··</ds:component>
321132 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-ocil.xml"·timestamp="2025-02-28T20:08:00">321132 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-ocil.xml"·timestamp="2025-03-01T22:08:00">
321133 ····<ocil:ocil>321133 ····<ocil:ocil>
321134 ······<ocil:generator>321134 ······<ocil:generator>
321135 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>321135 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
321136 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>321136 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
321137 ········<ocil:schema_version>2.0</ocil:schema_version>321137 ········<ocil:schema_version>2.0</ocil:schema_version>
321138 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>321138 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
321139 ······</ocil:generator>321139 ······</ocil:generator>
321140 ······<ocil:questionnaires>321140 ······<ocil:questionnaires>
321141 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_ocil:questionnaire:1">321141 ········<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1">
321142 ··········<ocil:title>Configure·Auto·Configuration·on·All·IPv6·Interfaces</ocil:title>321142 ··········<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title>
321143 ··········<ocil:actions>321143 ··········<ocil:actions>
321144 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_action:testaction:1</ocil:test_action_ref>321144 ············<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref>
321145 ··········</ocil:actions>321145 ··········</ocil:actions>
321146 ········</ocil:questionnaire>321146 ········</ocil:questionnaire>
321147 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order_ocil:questionnaire:1"> 
321148 ··········<ocil:title>Ensure·auditd·Unauthorized·Access·Attempts·To·open_by_handle_at·Are·Ordered·Correctly</ocil:title>321147 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1">
 321148 ··········<ocil:title>Kernel·panic·oops</ocil:title>
321149 ··········<ocil:actions>321149 ··········<ocil:actions>
321150 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order_action:testaction:1</ocil:test_action_ref>321150 ············<ocil:test_action_ref>ocil:ssg-kernel_config_panic_on_oops_action:testaction:1</ocil:test_action_ref>
321151 ··········</ocil:actions>321151 ··········</ocil:actions>
321152 ········</ocil:questionnaire>321152 ········</ocil:questionnaire>
321153 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1">321153 ········<ocil:questionnaire·id="ocil:ssg-dir_system_commands_root_owned_ocil:questionnaire:1">
321154 ··········<ocil:title>Enable·Yama·support</ocil:title>321154 ··········<ocil:title>Verify·that·system·commands·directories·have·root·ownership</ocil:title>
321155 ··········<ocil:actions>321155 ··········<ocil:actions>
321156 ············<ocil:test_action_ref>ocil:ssg-kernel_config_security_yama_action:testaction:1</ocil:test_action_ref>321156 ············<ocil:test_action_ref>ocil:ssg-dir_system_commands_root_owned_action:testaction:1</ocil:test_action_ref>
321157 ··········</ocil:actions>321157 ··········</ocil:actions>
321158 ········</ocil:questionnaire>321158 ········</ocil:questionnaire>
321159 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_chown_ocil:questionnaire:1">321159 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_postqueue_ocil:questionnaire:1">
321160 ··········<ocil:title>Record·Unsuccessful·Ownership·Changes·to·Files·-·chown</ocil:title>321160 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·postqueue</ocil:title>
321161 ··········<ocil:actions>321161 ··········<ocil:actions>
321162 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_chown_action:testaction:1</ocil:test_action_ref>321162 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_postqueue_action:testaction:1</ocil:test_action_ref>
321163 ··········</ocil:actions>321163 ··········</ocil:actions>
321164 ········</ocil:questionnaire>321164 ········</ocil:questionnaire>
321165 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_audit_auditd_ocil:questionnaire:1">321165 ········<ocil:questionnaire·id="ocil:ssg-sebool_ssh_chroot_rw_homedirs_ocil:questionnaire:1">
321166 ··········<ocil:title>Verify·Permissions·on·/etc/audit/auditd.conf</ocil:title>321166 ··········<ocil:title>Disable·the·ssh_chroot_rw_homedirs·SELinux·Boolean</ocil:title>
321167 ··········<ocil:actions>321167 ··········<ocil:actions>
321168 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_audit_auditd_action:testaction:1</ocil:test_action_ref>321168 ············<ocil:test_action_ref>ocil:ssg-sebool_ssh_chroot_rw_homedirs_action:testaction:1</ocil:test_action_ref>
321169 ··········</ocil:actions>321169 ··········</ocil:actions>
321170 ········</ocil:questionnaire>321170 ········</ocil:questionnaire>
321171 ········<ocil:questionnaire·id="ocil:ssg-rpm_verify_permissions_ocil:questionnaire:1">321171 ········<ocil:questionnaire·id="ocil:ssg-chronyd_or_ntpd_set_maxpoll_ocil:questionnaire:1">
321172 ··········<ocil:title>Verify·and·Correct·File·Permissions·with·RPM</ocil:title>321172 ··········<ocil:title>Configure·Time·Service·Maxpoll·Interval</ocil:title>
321173 ··········<ocil:actions>321173 ··········<ocil:actions>
321174 ············<ocil:test_action_ref>ocil:ssg-rpm_verify_permissions_action:testaction:1</ocil:test_action_ref>321174 ············<ocil:test_action_ref>ocil:ssg-chronyd_or_ntpd_set_maxpoll_action:testaction:1</ocil:test_action_ref>
321175 ··········</ocil:actions>321175 ··········</ocil:actions>
321176 ········</ocil:questionnaire>321176 ········</ocil:questionnaire>
321177 ········<ocil:questionnaire·id="ocil:ssg-service_rsyslog_enabled_ocil:questionnaire:1">321177 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_no_sanity_ocil:questionnaire:1">
321178 ··········<ocil:title>Enable·rsyslog·Service</ocil:title>321178 ··········<ocil:title>Enable·poison·without·sanity·check</ocil:title>
321179 ··········<ocil:actions>321179 ··········<ocil:actions>
Max diff block lines reached; 2703592/2715051 bytes (99.58%) of diff not shown.
2.48 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ocil.xml
2.48 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ocil.xml
Ordering differences only
    
Offset 3, 10512 lines modifiedOffset 3, 10512 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_ocil:questionnaire:1"> 
11 ······<ocil:title>Configure·Auto·Configuration·on·All·IPv6·Interfaces</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1">
 11 ······<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order_ocil:questionnaire:1"> 
17 ······<ocil:title>Ensure·auditd·Unauthorized·Access·Attempts·To·open_by_handle_at·Are·Ordered·Correctly</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1">
 17 ······<ocil:title>Kernel·panic·oops</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_on_oops_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1"> 
23 ······<ocil:title>Enable·Yama·support</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-dir_system_commands_root_owned_ocil:questionnaire:1">
 23 ······<ocil:title>Verify·that·system·commands·directories·have·root·ownership</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_yama_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-dir_system_commands_root_owned_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_chown_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_postqueue_ocil:questionnaire:1">
29 ······<ocil:title>Record·Unsuccessful·Ownership·Changes·to·Files·-·chown</ocil:title>29 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·postqueue</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_chown_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_postqueue_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_audit_auditd_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sebool_ssh_chroot_rw_homedirs_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Permissions·on·/etc/audit/auditd.conf</ocil:title>35 ······<ocil:title>Disable·the·ssh_chroot_rw_homedirs·SELinux·Boolean</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_audit_auditd_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sebool_ssh_chroot_rw_homedirs_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_permissions_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-chronyd_or_ntpd_set_maxpoll_ocil:questionnaire:1">
41 ······<ocil:title>Verify·and·Correct·File·Permissions·with·RPM</ocil:title>41 ······<ocil:title>Configure·Time·Service·Maxpoll·Interval</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-rpm_verify_permissions_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-chronyd_or_ntpd_set_maxpoll_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-service_rsyslog_enabled_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_no_sanity_ocil:questionnaire:1">
47 ······<ocil:title>Enable·rsyslog·Service</ocil:title>47 ······<ocil:title>Enable·poison·without·sanity·check</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-service_rsyslog_enabled_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_no_sanity_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-enable_fips_mode_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_dir_ocil:questionnaire:1">
53 ······<ocil:title>Enable·FIPS·Mode</ocil:title>53 ······<ocil:title>Account·Lockouts·Must·Persist</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-enable_fips_mode_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_sudoers_ocil:questionnaire:1"> 
59 ······<ocil:title>Verify·Permissions·On·/etc/sudoers·File</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-timer_dnf-automatic_enabled_ocil:questionnaire:1">
 59 ······<ocil:title>Enable·dnf-automatic·Timer</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_sudoers_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-timer_dnf-automatic_enabled_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_creat_ocil:questionnaire:1"> 
65 ······<ocil:title>Record·Unsuccessful·Creation·Attempts·to·Files·-·openat·O_CREAT</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1">
 65 ······<ocil:title>Disable·kernel·debugfs</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_creat_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_slub_debug_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-service_fapolicyd_enabled_ocil:questionnaire:1">
71 ······<ocil:title>Enable·SLUB·debugging·support</ocil:title>71 ······<ocil:title>Enable·the·File·Access·Policy·Service</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_slub_debug_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-service_fapolicyd_enabled_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_autorun_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">
77 ······<ocil:title>Disable·GNOME3·Automount·running</ocil:title>77 ······<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_autorun_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-mount_option_krb_sec_remote_filesystems_ocil:questionnaire:1"> 
83 ······<ocil:title>Mount·Remote·Filesystems·with·Kerberos·Security</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_passwd_timeout_ocil:questionnaire:1">
 83 ······<ocil:title>Ensure·sudo·passwd_timeout·is·appropriate·-·sudo·passwd_timeout</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-mount_option_krb_sec_remote_filesystems_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sudo_add_passwd_timeout_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_gssapi_auth_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_creat_ocil:questionnaire:1">
89 ······<ocil:title>Enable·GSSAPI·Authentication</ocil:title>89 ······<ocil:title>Record·Successful·Access·Attempts·to·Files·-·creat</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_gssapi_auth_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_creat_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1"> 
95 ······<ocil:title>Remove·NIS·Client</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ssh_keysign_ocil:questionnaire:1">
 95 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·ssh-keysign</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_ssh_keysign_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">
101 ······<ocil:title>Deactivate·Wireless·Network·Interfaces</ocil:title>101 ······<ocil:title>Verify·Owner·on·crontab</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dictcheck_ocil:questionnaire:1"> 
107 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Prevent·the·Use·of·Dictionary·Words</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">
 107 ······<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dictcheck_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_nosuid_ocil:questionnaire:1">
113 ······<ocil:title>Kernel·panic·timeout</ocil:title>113 ······<ocil:title>Add·nosuid·Option·to·/boot</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_timeout_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_nosuid_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_usr_share_ocil:questionnaire:1"> 
119 ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls·in·usr/share</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_perf_event_paranoid_ocil:questionnaire:1">
 119 ······<ocil:title>Disallow·kernel·profiling·by·unprivileged·users</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
Max diff block lines reached; 2588513/2600987 bytes (99.52%) of diff not shown.
2.27 KB
./usr/share/xml/scap/ssg/content/ssg-ol8-xccdf.xml
2.17 KB
./usr/share/xml/scap/ssg/content/ssg-ol8-xccdf.xml
Ordering differences only
    
Offset 351, 25 lines modifiedOffset 351, 25 lines modified
351 ······</cpe-lang:logical-test>351 ······</cpe-lang:logical-test>
352 ····</cpe-lang:platform>352 ····</cpe-lang:platform>
353 ····<cpe-lang:platform·id="package_bash">353 ····<cpe-lang:platform·id="package_bash">
354 ······<cpe-lang:logical-test·operator="AND"·negate="false">354 ······<cpe-lang:logical-test·operator="AND"·negate="false">
355 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>355 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
356 ······</cpe-lang:logical-test>356 ······</cpe-lang:logical-test>
357 ····</cpe-lang:platform>357 ····</cpe-lang:platform>
358 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
359 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
360 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
361 ······</cpe-lang:logical-test> 
362 ····</cpe-lang:platform> 
363 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">358 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
364 ······<cpe-lang:logical-test·operator="AND"·negate="false">359 ······<cpe-lang:logical-test·operator="AND"·negate="false">
365 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>360 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
366 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>361 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
367 ······</cpe-lang:logical-test>362 ······</cpe-lang:logical-test>
368 ····</cpe-lang:platform>363 ····</cpe-lang:platform>
 364 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 365 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 366 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 367 ······</cpe-lang:logical-test>
 368 ····</cpe-lang:platform>
369 ····<cpe-lang:platform·id="not_s390x_arch">369 ····<cpe-lang:platform·id="not_s390x_arch">
370 ······<cpe-lang:logical-test·operator="AND"·negate="false">370 ······<cpe-lang:logical-test·operator="AND"·negate="false">
371 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>371 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
372 ······</cpe-lang:logical-test>372 ······</cpe-lang:logical-test>
373 ····</cpe-lang:platform>373 ····</cpe-lang:platform>
374 ····<cpe-lang:platform·id="package_tmux">374 ····<cpe-lang:platform·id="package_tmux">
375 ······<cpe-lang:logical-test·operator="AND"·negate="false">375 ······<cpe-lang:logical-test·operator="AND"·negate="false">
2.06 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds.xml
2.06 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol9.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol9.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol9.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol9.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:9">30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:9">
31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·9</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·9</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml">oval:ssg-installed_OS_is_ol9:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml">oval:ssg-installed_OS_is_ol9:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·9</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·9</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Oracle·Linux·9.·It·is·a·rendering·of42 configuration·settings·for·Oracle·Linux·9.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 204458, 15 lines modifiedOffset 204458, 15 lines modified
204458 ··············<xccdf-1.2:check-content-ref·href="ssg-ol9-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ocil:questionnaire:1"/>204458 ··············<xccdf-1.2:check-content-ref·href="ssg-ol9-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ocil:questionnaire:1"/>
204459 ············</xccdf-1.2:check>204459 ············</xccdf-1.2:check>
204460 ··········</xccdf-1.2:Rule>204460 ··········</xccdf-1.2:Rule>
204461 ········</xccdf-1.2:Group>204461 ········</xccdf-1.2:Group>
204462 ······</xccdf-1.2:Group>204462 ······</xccdf-1.2:Group>
204463 ····</xccdf-1.2:Benchmark>204463 ····</xccdf-1.2:Benchmark>
204464 ··</ds:component>204464 ··</ds:component>
204465 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-oval.xml"·timestamp="2025-02-28T20:08:00">204465 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-oval.xml"·timestamp="2025-03-01T22:08:00">
204466 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">204466 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
204467 ······<oval-def:generator>204467 ······<oval-def:generator>
204468 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>204468 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
204469 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>204469 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
204470 ········<oval:schema_version>5.11</oval:schema_version>204470 ········<oval:schema_version>5.11</oval:schema_version>
204471 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>204471 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
204472 ······</oval-def:generator>204472 ······</oval-def:generator>
Offset 250354, 7517 lines modifiedOffset 250354, 7517 lines modified
250354 ············</oval-def:arithmetic>250354 ············</oval-def:arithmetic>
250355 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>250355 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
250356 ··········</oval-def:arithmetic>250356 ··········</oval-def:arithmetic>
250357 ········</oval-def:local_variable>250357 ········</oval-def:local_variable>
250358 ······</oval-def:variables>250358 ······</oval-def:variables>
250359 ····</oval-def:oval_definitions>250359 ····</oval-def:oval_definitions>
250360 ··</ds:component>250360 ··</ds:component>
250361 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-ocil.xml"·timestamp="2025-02-28T20:08:00">250361 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-ocil.xml"·timestamp="2025-03-01T22:08:00">
250362 ····<ocil:ocil>250362 ····<ocil:ocil>
250363 ······<ocil:generator>250363 ······<ocil:generator>
250364 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>250364 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
250365 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>250365 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
250366 ········<ocil:schema_version>2.0</ocil:schema_version>250366 ········<ocil:schema_version>2.0</ocil:schema_version>
250367 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>250367 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
250368 ······</ocil:generator>250368 ······</ocil:generator>
250369 ······<ocil:questionnaires>250369 ······<ocil:questionnaires>
250370 ········<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_regular_ocil:questionnaire:1">250370 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_ocil:questionnaire:1">
250371 ··········<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Regular·files</ocil:title>250371 ··········<ocil:title>Configure·Maximum·Number·of·Autoconfigured·Addresses·on·All·IPv6·Interfaces</ocil:title>
250372 ··········<ocil:actions>250372 ··········<ocil:actions>
250373 ············<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_regular_action:testaction:1</ocil:test_action_ref>250373 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_action:testaction:1</ocil:test_action_ref>
250374 ··········</ocil:actions>250374 ··········</ocil:actions>
250375 ········</ocil:questionnaire>250375 ········</ocil:questionnaire>
250376 ········<ocil:questionnaire·id="ocil:ssg-security_patches_up_to_date_ocil:questionnaire:1">250376 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1">
250377 ··········<ocil:title>Ensure·Software·Patches·Installed</ocil:title>250377 ··········<ocil:title>Configure·auditd·space_left·on·Low·Disk·Space</ocil:title>
250378 ··········<ocil:actions>250378 ··········<ocil:actions>
250379 ············<ocil:test_action_ref>ocil:ssg-security_patches_up_to_date_action:testaction:1</ocil:test_action_ref>250379 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action:testaction:1</ocil:test_action_ref>
250380 ··········</ocil:actions>250380 ··········</ocil:actions>
250381 ········</ocil:questionnaire>250381 ········</ocil:questionnaire>
250382 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1">250382 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1">
250383 ··········<ocil:title>Remove·the·kernel·mapping·in·user·mode</ocil:title>250383 ··········<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>
250384 ··········<ocil:actions>250384 ··········<ocil:actions>
250385 ············<ocil:test_action_ref>ocil:ssg-kernel_config_page_table_isolation_action:testaction:1</ocil:test_action_ref>250385 ············<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>
250386 ··········</ocil:actions>250386 ··········</ocil:actions>
250387 ········</ocil:questionnaire>250387 ········</ocil:questionnaire>
250388 ········<ocil:questionnaire·id="ocil:ssg-harden_ssh_client_crypto_policy_ocil:questionnaire:1">250388 ········<ocil:questionnaire·id="ocil:ssg-service_avahi-daemon_disabled_ocil:questionnaire:1">
250389 ··········<ocil:title>Harden·SSH·client·Crypto·Policy</ocil:title>250389 ··········<ocil:title>Disable·Avahi·Server·Software</ocil:title>
250390 ··········<ocil:actions>250390 ··········<ocil:actions>
250391 ············<ocil:test_action_ref>ocil:ssg-harden_ssh_client_crypto_policy_action:testaction:1</ocil:test_action_ref>250391 ············<ocil:test_action_ref>ocil:ssg-service_avahi-daemon_disabled_action:testaction:1</ocil:test_action_ref>
250392 ··········</ocil:actions>250392 ··········</ocil:actions>
250393 ········</ocil:questionnaire>250393 ········</ocil:questionnaire>
250394 ········<ocil:questionnaire·id="ocil:ssg-package_sendmail_removed_ocil:questionnaire:1">250394 ········<ocil:questionnaire·id="ocil:ssg-configure_bashrc_exec_tmux_ocil:questionnaire:1">
250395 ··········<ocil:title>Uninstall·Sendmail·Package</ocil:title>250395 ··········<ocil:title>Support·session·locking·with·tmux</ocil:title>
250396 ··········<ocil:actions>250396 ··········<ocil:actions>
250397 ············<ocil:test_action_ref>ocil:ssg-package_sendmail_removed_action:testaction:1</ocil:test_action_ref>250397 ············<ocil:test_action_ref>ocil:ssg-configure_bashrc_exec_tmux_action:testaction:1</ocil:test_action_ref>
250398 ··········</ocil:actions>250398 ··········</ocil:actions>
250399 ········</ocil:questionnaire>250399 ········</ocil:questionnaire>
250400 ········<ocil:questionnaire·id="ocil:ssg-enable_dracut_fips_module_ocil:questionnaire:1">250400 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_ocil:questionnaire:1">
250401 ··········<ocil:title>Enable·Dracut·FIPS·Module</ocil:title>250401 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv6·Interfaces</ocil:title>
250402 ··········<ocil:actions>250402 ··········<ocil:actions>
250403 ············<ocil:test_action_ref>ocil:ssg-enable_dracut_fips_module_action:testaction:1</ocil:test_action_ref>250403 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>
250404 ··········</ocil:actions>250404 ··········</ocil:actions>
250405 ········</ocil:questionnaire>250405 ········</ocil:questionnaire>
250406 ········<ocil:questionnaire·id="ocil:ssg-service_snmpd_disabled_ocil:questionnaire:1">250406 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1">
250407 ··········<ocil:title>Disable·snmpd·Service</ocil:title>250407 ··········<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
250408 ··········<ocil:actions>250408 ··········<ocil:actions>
250409 ············<ocil:test_action_ref>ocil:ssg-service_snmpd_disabled_action:testaction:1</ocil:test_action_ref>250409 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref>
250410 ··········</ocil:actions>250410 ··········</ocil:actions>
250411 ········</ocil:questionnaire>250411 ········</ocil:questionnaire>
250412 ········<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_ipsecd_ocil:questionnaire:1"> 
250413 ··········<ocil:title>Verify·User·Who·Owns·/etc/ipsec.d·Directory</ocil:title>250412 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1">
 250413 ··········<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>
250414 ··········<ocil:actions>250414 ··········<ocil:actions>
250415 ············<ocil:test_action_ref>ocil:ssg-directory_owner_etc_ipsecd_action:testaction:1</ocil:test_action_ref>250415 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref>
250416 ··········</ocil:actions>250416 ··········</ocil:actions>
250417 ········</ocil:questionnaire>250417 ········</ocil:questionnaire>
250418 ········<ocil:questionnaire·id="ocil:ssg-audit_access_failed_ocil:questionnaire:1">250418 ········<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1">
250419 ··········<ocil:title>Configure·auditing·of·unsuccessful·file·accesses</ocil:title>250419 ··········<ocil:title>Ensure·rsyslog·is·Installed</ocil:title>
250420 ··········<ocil:actions>250420 ··········<ocil:actions>
250421 ············<ocil:test_action_ref>ocil:ssg-audit_access_failed_action:testaction:1</ocil:test_action_ref>250421 ············<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>
250422 ··········</ocil:actions>250422 ··········</ocil:actions>
250423 ········</ocil:questionnaire>250423 ········</ocil:questionnaire>
250424 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_credentials_ocil:questionnaire:1">250424 ········<ocil:questionnaire·id="ocil:ssg-logind_session_timeout_ocil:questionnaire:1">
250425 ··········<ocil:title>Enable·checks·on·credential·management</ocil:title>250425 ··········<ocil:title>Configure·Logind·to·terminate·idle·sessions·after·certain·time·of·inactivity</ocil:title>
250426 ··········<ocil:actions>250426 ··········<ocil:actions>
250427 ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_credentials_action:testaction:1</ocil:test_action_ref>250427 ············<ocil:test_action_ref>ocil:ssg-logind_session_timeout_action:testaction:1</ocil:test_action_ref>
250428 ··········</ocil:actions>250428 ··········</ocil:actions>
250429 ········</ocil:questionnaire>250429 ········</ocil:questionnaire>
250430 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">250430 ········<ocil:questionnaire·id="ocil:ssg-timer_logrotate_enabled_ocil:questionnaire:1">
250431 ··········<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title>250431 ··········<ocil:title>Enable·logrotate·Timer</ocil:title>
250432 ··········<ocil:actions>250432 ··········<ocil:actions>
250433 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref>250433 ············<ocil:test_action_ref>ocil:ssg-timer_logrotate_enabled_action:testaction:1</ocil:test_action_ref>
250434 ··········</ocil:actions>250434 ··········</ocil:actions>
250435 ········</ocil:questionnaire>250435 ········</ocil:questionnaire>
250436 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1">250436 ········<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1">
250437 ··········<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>250437 ··········<ocil:title>Verify·iptables·Enabled</ocil:title>
250438 ··········<ocil:actions>250438 ··········<ocil:actions>
250439 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>250439 ············<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 2144553/2156974 bytes (99.42%) of diff not shown.
1.97 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ocil.xml
1.97 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ocil.xml
Ordering differences only
    
Offset 3, 7508 lines modifiedOffset 3, 7508 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_regular_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_ocil:questionnaire:1">
11 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Regular·files</ocil:title>11 ······<ocil:title>Configure·Maximum·Number·of·Autoconfigured·Addresses·on·All·IPv6·Interfaces</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_regular_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-security_patches_up_to_date_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1">
17 ······<ocil:title>Ensure·Software·Patches·Installed</ocil:title>17 ······<ocil:title>Configure·auditd·space_left·on·Low·Disk·Space</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-security_patches_up_to_date_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1">
23 ······<ocil:title>Remove·the·kernel·mapping·in·user·mode</ocil:title>23 ······<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_table_isolation_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-harden_ssh_client_crypto_policy_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-service_avahi-daemon_disabled_ocil:questionnaire:1">
29 ······<ocil:title>Harden·SSH·client·Crypto·Policy</ocil:title>29 ······<ocil:title>Disable·Avahi·Server·Software</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-harden_ssh_client_crypto_policy_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-service_avahi-daemon_disabled_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-package_sendmail_removed_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-configure_bashrc_exec_tmux_ocil:questionnaire:1">
35 ······<ocil:title>Uninstall·Sendmail·Package</ocil:title>35 ······<ocil:title>Support·session·locking·with·tmux</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-package_sendmail_removed_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-configure_bashrc_exec_tmux_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-enable_dracut_fips_module_ocil:questionnaire:1"> 
41 ······<ocil:title>Enable·Dracut·FIPS·Module</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_ocil:questionnaire:1">
 41 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv6·Interfaces</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-enable_dracut_fips_module_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-service_snmpd_disabled_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1">
47 ······<ocil:title>Disable·snmpd·Service</ocil:title>47 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-service_snmpd_disabled_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_ipsecd_ocil:questionnaire:1"> 
53 ······<ocil:title>Verify·User·Who·Owns·/etc/ipsec.d·Directory</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1">
 53 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-directory_owner_etc_ipsecd_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_access_failed_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1">
59 ······<ocil:title>Configure·auditing·of·unsuccessful·file·accesses</ocil:title>59 ······<ocil:title>Ensure·rsyslog·is·Installed</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_access_failed_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_credentials_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-logind_session_timeout_ocil:questionnaire:1">
65 ······<ocil:title>Enable·checks·on·credential·management</ocil:title>65 ······<ocil:title>Configure·Logind·to·terminate·idle·sessions·after·certain·time·of·inactivity</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_credentials_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-logind_session_timeout_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-timer_logrotate_enabled_ocil:questionnaire:1">
71 ······<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title>71 ······<ocil:title>Enable·logrotate·Timer</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-timer_logrotate_enabled_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1"> 
77 ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1">
 77 ······<ocil:title>Verify·iptables·Enabled</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sshd_x11_use_localhost_ocil:questionnaire:1">
83 ······<ocil:title>Enable·automatic·signing·of·all·modules</ocil:title>83 ······<ocil:title>Prevent·remote·hosts·from·connecting·to·the·proxy·display</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_all_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sshd_x11_use_localhost_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-package_nfs-utils_removed_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1">
89 ······<ocil:title>Uninstall·nfs-utils·Package</ocil:title>89 ······<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-package_nfs-utils_removed_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_unprivileged_bpf_disabled_accept_default_ocil:questionnaire:1"> 
95 ······<ocil:title>Disable·Access·to·Network·bpf()·Syscall·From·Unprivileged·Processes</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_mount_ocil:questionnaire:1">
 95 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·mount</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_unprivileged_bpf_disabled_accept_default_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_mount_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_grpquota_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_binary_dirs_ocil:questionnaire:1">
101 ······<ocil:title>Add·grpquota·Option·to·/home</ocil:title>101 ······<ocil:title>Verify·that·System·Executables·Have·Root·Ownership</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_grpquota_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_chrony_keys_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-harden_ssh_client_crypto_policy_ocil:questionnaire:1">
107 ······<ocil:title>Verify·User·Who·Owns·/etc/chrony.keys·File</ocil:title>107 ······<ocil:title>Harden·SSH·client·Crypto·Policy</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_chrony_keys_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-harden_ssh_client_crypto_policy_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-no_host_based_files_ocil:questionnaire:1">
113 ······<ocil:title>Verify·Permissions·on·gshadow·File</ocil:title>113 ······<ocil:title>Remove·Host-Based·Authentication·Files</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_gshadow_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-no_host_based_files_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·unix_chkpwd</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_max_life_existing_ocil:questionnaire:1">
 119 ······<ocil:title>Set·Existing·Passwords·Maximum·Age</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_existing_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-sshd_x11_use_localhost_ocil:questionnaire:1"> 
Max diff block lines reached; 2053362/2066189 bytes (99.38%) of diff not shown.
939 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ds.xml
939 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:harden:">28 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:harden:">
29 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Harden·distribution</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Harden·distribution</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_oeharden:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_oeharden:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:nodistro:">32 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:nodistro:">
33 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·nodistro</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·nodistro</cpe-dict:title>
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:poky:">40 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:poky:">
41 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Poky·reference·distribution</cpe-dict:title>41 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Poky·reference·distribution</cpe-dict:title>
42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_poky:def:1</cpe-dict:check>42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_poky:def:1</cpe-dict:check>
43 ······</cpe-dict:cpe-item>43 ······</cpe-dict:cpe-item>
44 ····</cpe-dict:cpe-list>44 ····</cpe-dict:cpe-list>
45 ··</ds:component>45 ··</ds:component>
46 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-xccdf.xml"·timestamp="2025-02-28T20:08:00">46 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-xccdf.xml"·timestamp="2025-03-01T22:08:00">
47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEMBEDDED"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEMBEDDED"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·OpenEmbedded</xccdf-1.2:title>49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·OpenEmbedded</xccdf-1.2:title>
50 ······<xccdf-1.2:description>50 ······<xccdf-1.2:description>
51 ········This·guide·presents·a·catalog·of·security-relevant51 ········This·guide·presents·a·catalog·of·security-relevant
52 configuration·settings·for·OpenEmbedded.·It·is·a·rendering·of52 configuration·settings·for·OpenEmbedded.·It·is·a·rendering·of
53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 59078, 15 lines modifiedOffset 59078, 15 lines modified
59078 ··············<xccdf-1.2:check-content-ref·href="ssg-openembedded-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>59078 ··············<xccdf-1.2:check-content-ref·href="ssg-openembedded-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
59079 ············</xccdf-1.2:check>59079 ············</xccdf-1.2:check>
59080 ··········</xccdf-1.2:Rule>59080 ··········</xccdf-1.2:Rule>
59081 ········</xccdf-1.2:Group>59081 ········</xccdf-1.2:Group>
59082 ······</xccdf-1.2:Group>59082 ······</xccdf-1.2:Group>
59083 ····</xccdf-1.2:Benchmark>59083 ····</xccdf-1.2:Benchmark>
59084 ··</ds:component>59084 ··</ds:component>
59085 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-oval.xml"·timestamp="2025-02-28T20:08:00">59085 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-oval.xml"·timestamp="2025-03-01T22:08:00">
59086 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">59086 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
59087 ······<oval-def:generator>59087 ······<oval-def:generator>
59088 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>59088 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
59089 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>59089 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
59090 ········<oval:schema_version>5.11</oval:schema_version>59090 ········<oval:schema_version>5.11</oval:schema_version>
59091 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>59091 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
59092 ······</oval-def:generator>59092 ······</oval-def:generator>
Offset 81150, 3634 lines modifiedOffset 81150, 3634 lines modified
81150 ············</oval-def:arithmetic>81150 ············</oval-def:arithmetic>
81151 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>81151 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
81152 ··········</oval-def:arithmetic>81152 ··········</oval-def:arithmetic>
81153 ········</oval-def:local_variable>81153 ········</oval-def:local_variable>
81154 ······</oval-def:variables>81154 ······</oval-def:variables>
81155 ····</oval-def:oval_definitions>81155 ····</oval-def:oval_definitions>
81156 ··</ds:component>81156 ··</ds:component>
81157 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-ocil.xml"·timestamp="2025-02-28T20:08:00">81157 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-ocil.xml"·timestamp="2025-03-01T22:08:00">
81158 ····<ocil:ocil>81158 ····<ocil:ocil>
81159 ······<ocil:generator>81159 ······<ocil:generator>
81160 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>81160 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
81161 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>81161 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
81162 ········<ocil:schema_version>2.0</ocil:schema_version>81162 ········<ocil:schema_version>2.0</ocil:schema_version>
81163 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>81163 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
81164 ······</ocil:generator>81164 ······</ocil:generator>
81165 ······<ocil:questionnaires>81165 ······<ocil:questionnaires>
81166 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_all_shadowed_ocil:questionnaire:1">81166 ········<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">
81167 ··········<ocil:title>Verify·All·Account·Password·Hashes·are·Shadowed</ocil:title>81167 ··········<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>
81168 ··········<ocil:actions>81168 ··········<ocil:actions>
81169 ············<ocil:test_action_ref>ocil:ssg-accounts_password_all_shadowed_action:testaction:1</ocil:test_action_ref>81169 ············<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>
81170 ··········</ocil:actions>81170 ··········</ocil:actions>
81171 ········</ocil:questionnaire>81171 ········</ocil:questionnaire>
81172 ········<ocil:questionnaire·id="ocil:ssg-package_postfix_installed_ocil:questionnaire:1">81172 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_gshadow_ocil:questionnaire:1">
81173 ··········<ocil:title>The·Postfix·package·is·installed</ocil:title>81173 ··········<ocil:title>Verify·Group·Who·Owns·gshadow·File</ocil:title>
81174 ··········<ocil:actions>81174 ··········<ocil:actions>
81175 ············<ocil:test_action_ref>ocil:ssg-package_postfix_installed_action:testaction:1</ocil:test_action_ref>81175 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_gshadow_action:testaction:1</ocil:test_action_ref>
81176 ··········</ocil:actions>81176 ··········</ocil:actions>
81177 ········</ocil:questionnaire>81177 ········</ocil:questionnaire>
81178 ········<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1">81178 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_ocil:questionnaire:1">
81179 ··········<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title>81179 ··········<ocil:title>Configure·Response·Mode·of·ARP·Requests·for·All·IPv4·Interfaces</ocil:title>
81180 ··········<ocil:actions>81180 ··········<ocil:actions>
81181 ············<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref>81181 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_action:testaction:1</ocil:test_action_ref>
81182 ··········</ocil:actions>81182 ··········</ocil:actions>
81183 ········</ocil:questionnaire>81183 ········</ocil:questionnaire>
81184 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">81184 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">
81185 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>81185 ··········<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>
81186 ··········<ocil:actions>81186 ··········<ocil:actions>
81187 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>81187 ············<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>
81188 ··········</ocil:actions>81188 ··········</ocil:actions>
81189 ········</ocil:questionnaire>81189 ········</ocil:questionnaire>
81190 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">81190 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_rds_disabled_ocil:questionnaire:1">
81191 ··········<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>81191 ··········<ocil:title>Disable·RDS·Support</ocil:title>
81192 ··········<ocil:actions>81192 ··········<ocil:actions>
81193 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>81193 ············<ocil:test_action_ref>ocil:ssg-kernel_module_rds_disabled_action:testaction:1</ocil:test_action_ref>
81194 ··········</ocil:actions>81194 ··········</ocil:actions>
81195 ········</ocil:questionnaire>81195 ········</ocil:questionnaire>
81196 ········<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1"> 
81197 ··········<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>81196 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1">
 81197 ··········<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title>
81198 ··········<ocil:actions>81198 ··········<ocil:actions>
81199 ············<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>81199 ············<ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>
81200 ··········</ocil:actions>81200 ··········</ocil:actions>
81201 ········</ocil:questionnaire>81201 ········</ocil:questionnaire>
81202 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">81202 ········<ocil:questionnaire·id="ocil:ssg-service_crond_enabled_ocil:questionnaire:1">
81203 ··········<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>81203 ··········<ocil:title>Enable·cron·Service</ocil:title>
81204 ··········<ocil:actions>81204 ··········<ocil:actions>
81205 ············<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>81205 ············<ocil:test_action_ref>ocil:ssg-service_crond_enabled_action:testaction:1</ocil:test_action_ref>
81206 ··········</ocil:actions>81206 ··········</ocil:actions>
81207 ········</ocil:questionnaire>81207 ········</ocil:questionnaire>
81208 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">81208 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_hourly_ocil:questionnaire:1">
81209 ··········<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>81209 ··········<ocil:title>Verify·Permissions·on·cron.hourly</ocil:title>
81210 ··········<ocil:actions>81210 ··········<ocil:actions>
81211 ············<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>81211 ············<ocil:test_action_ref>ocil:ssg-file_permissions_cron_hourly_action:testaction:1</ocil:test_action_ref>
81212 ··········</ocil:actions>81212 ··········</ocil:actions>
81213 ········</ocil:questionnaire>81213 ········</ocil:questionnaire>
81214 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1"> 
81215 ··········<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·by·Default</ocil:title>81214 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_syslog_ocil:questionnaire:1">
 81215 ··········<ocil:title>Verify·Group·Who·Owns·/var/log/syslog·File</ocil:title>
81216 ··········<ocil:actions>81216 ··········<ocil:actions>
81217 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_action:testaction:1</ocil:test_action_ref>81217 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_syslog_action:testaction:1</ocil:test_action_ref>
81218 ··········</ocil:actions>81218 ··········</ocil:actions>
81219 ········</ocil:questionnaire>81219 ········</ocil:questionnaire>
81220 ········<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1">81220 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">
81221 ··········<ocil:title>Ensure·gpgcheck·Enabled·In·Main·dnf·Configuration</ocil:title>81221 ··········<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>
81222 ··········<ocil:actions>81222 ··········<ocil:actions>
81223 ············<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>81223 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>
81224 ··········</ocil:actions>81224 ··········</ocil:actions>
81225 ········</ocil:questionnaire>81225 ········</ocil:questionnaire>
81226 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_ip_forward_ocil:questionnaire:1">81226 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1">
Max diff block lines reached; 948856/960930 bytes (98.74%) of diff not shown.
894 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ocil.xml
894 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ocil.xml
Ordering differences only
    
Offset 3, 3625 lines modifiedOffset 3, 3625 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_all_shadowed_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">
11 ······<ocil:title>Verify·All·Account·Password·Hashes·are·Shadowed</ocil:title>11 ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-accounts_password_all_shadowed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-package_postfix_installed_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_gshadow_ocil:questionnaire:1">
17 ······<ocil:title>The·Postfix·package·is·installed</ocil:title>17 ······<ocil:title>Verify·Group·Who·Owns·gshadow·File</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_postfix_installed_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_gshadow_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title>23 ······<ocil:title>Configure·Response·Mode·of·ARP·Requests·for·All·IPv4·Interfaces</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">
29 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>29 ······<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_rds_disabled_ocil:questionnaire:1">
35 ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>35 ······<ocil:title>Disable·RDS·Support</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-kernel_module_rds_disabled_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1"> 
41 ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1">
 41 ······<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-service_crond_enabled_ocil:questionnaire:1">
47 ······<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>47 ······<ocil:title>Enable·cron·Service</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-service_crond_enabled_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_hourly_ocil:questionnaire:1">
53 ······<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>53 ······<ocil:title>Verify·Permissions·on·cron.hourly</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_hourly_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1"> 
59 ······<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·by·Default</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_syslog_ocil:questionnaire:1">
 59 ······<ocil:title>Verify·Group·Who·Owns·/var/log/syslog·File</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_syslog_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·gpgcheck·Enabled·In·Main·dnf·Configuration</ocil:title>65 ······<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_ip_forward_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1">
71 ······<ocil:title>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</ocil:title>71 ······<ocil:title>Verify·Permissions·on·/etc/at.allow·file</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_forward_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_at_allow_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1">
77 ······<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title>77 ······<ocil:title>Set·Password·Minimum·Age</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_poweroff_ocil:questionnaire:1"> 
83 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·poweroff</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_x86_vsyscall_emulation_ocil:questionnaire:1">
 83 ······<ocil:title>Disable·x86·vsyscall·emulation</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_poweroff_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_x86_vsyscall_emulation_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_group_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_cron_deny_not_exist_ocil:questionnaire:1">
89 ······<ocil:title>Verify·User·Who·Owns·Backup·group·File</ocil:title>89 ······<ocil:title>Ensure·that·/etc/cron.deny·does·not·exist</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_group_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_cron_deny_not_exist_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1">
95 ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>95 ······<ocil:title>Modify·the·System·Login·Banner</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_d_ocil:questionnaire:1">
101 ······<ocil:title>Disable·Kerberos·Authentication</ocil:title>101 ······<ocil:title>Verify·Group·Who·Owns·cron.d</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_d_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_audit_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-package_MFEhiplsm_installed_ocil:questionnaire:1">
107 ······<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>107 ······<ocil:title>Install·the·Host·Intrusion·Prevention·System·(HIPS)·Module</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-package_MFEhiplsm_installed_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1">
113 ······<ocil:title>Enable·Encrypted·X11·Forwarding</ocil:title>113 ······<ocil:title>Do·Not·Allow·SSH·Environment·Options</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">
119 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>119 ······<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_list_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_renameat_ocil:questionnaire:1">
125 ······<ocil:title>Enable·checks·on·linked·list·manipulation</ocil:title>125 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·renameat</ocil:title>
126 ······<ocil:actions>126 ······<ocil:actions>
Max diff block lines reached; 902618/915556 bytes (98.59%) of diff not shown.
560 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ds.xml
560 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS:ga:server">28 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS:ga:server">
29 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP1:ga:server">32 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP1:ga:server">
33 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP1</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP1</cpe-dict:title>
Offset 35, 15 lines modifiedOffset 35, 15 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP2:ga:server">36 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP2:ga:server">
37 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP2</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP2</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-xccdf.xml"·timestamp="2025-02-28T20:08:00">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-xccdf.xml"·timestamp="2025-03-01T22:08:00">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEULER2203"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEULER2203"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openEuler·2203</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openEuler·2203</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·openEuler·2203.·It·is·a·rendering·of48 configuration·settings·for·openEuler·2203.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 39461, 15 lines modifiedOffset 39461, 15 lines modified
39461 ··············<xccdf-1.2:check-content-ref·href="ssg-openeuler2203-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"/>39461 ··············<xccdf-1.2:check-content-ref·href="ssg-openeuler2203-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"/>
39462 ············</xccdf-1.2:check>39462 ············</xccdf-1.2:check>
39463 ··········</xccdf-1.2:Rule>39463 ··········</xccdf-1.2:Rule>
39464 ········</xccdf-1.2:Group>39464 ········</xccdf-1.2:Group>
39465 ······</xccdf-1.2:Group>39465 ······</xccdf-1.2:Group>
39466 ····</xccdf-1.2:Benchmark>39466 ····</xccdf-1.2:Benchmark>
39467 ··</ds:component>39467 ··</ds:component>
39468 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"·timestamp="2025-02-28T20:08:00">39468 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"·timestamp="2025-03-01T22:08:00">
39469 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">39469 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
39470 ······<oval-def:generator>39470 ······<oval-def:generator>
39471 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>39471 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
39472 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>39472 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
39473 ········<oval:schema_version>5.11</oval:schema_version>39473 ········<oval:schema_version>5.11</oval:schema_version>
39474 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>39474 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
39475 ······</oval-def:generator>39475 ······</oval-def:generator>
Offset 52232, 4510 lines modifiedOffset 52232, 4586 lines modified
52232 ············</oval-def:arithmetic>52232 ············</oval-def:arithmetic>
52233 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>52233 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
52234 ··········</oval-def:arithmetic>52234 ··········</oval-def:arithmetic>
52235 ········</oval-def:local_variable>52235 ········</oval-def:local_variable>
52236 ······</oval-def:variables>52236 ······</oval-def:variables>
52237 ····</oval-def:oval_definitions>52237 ····</oval-def:oval_definitions>
52238 ··</ds:component>52238 ··</ds:component>
52239 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"·timestamp="2025-02-28T20:08:00">52239 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"·timestamp="2025-03-01T22:08:00">
52240 ····<ocil:ocil>52240 ····<ocil:ocil>
52241 ······<ocil:generator>52241 ······<ocil:generator>
52242 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>52242 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
52243 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>52243 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
52244 ········<ocil:schema_version>2.0</ocil:schema_version>52244 ········<ocil:schema_version>2.0</ocil:schema_version>
52245 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>52245 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
52246 ······</ocil:generator>52246 ······</ocil:generator>
52247 ······<ocil:questionnaires>52247 ······<ocil:questionnaires>
52248 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1">52248 ········<ocil:questionnaire·id="ocil:ssg-accounts_tmout_ocil:questionnaire:1">
 52249 ··········<ocil:title>Set·Interactive·Session·Timeout</ocil:title>
52249 ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title> 
52250 ··········<ocil:actions> 
52251 ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref> 
52252 ··········</ocil:actions> 
52253 ········</ocil:questionnaire> 
52254 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1"> 
52255 ··········<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title> 
52256 ··········<ocil:actions> 
52257 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref> 
52258 ··········</ocil:actions> 
52259 ········</ocil:questionnaire> 
52260 ········<ocil:questionnaire·id="ocil:ssg-set_nftables_loopback_traffic_ocil:questionnaire:1"> 
52261 ··········<ocil:title>Set·nftables·Configuration·for·Loopback·Traffic</ocil:title> 
52262 ··········<ocil:actions>52250 ··········<ocil:actions>
52263 ············<ocil:test_action_ref>ocil:ssg-set_nftables_loopback_traffic_action:testaction:1</ocil:test_action_ref>52251 ············<ocil:test_action_ref>ocil:ssg-accounts_tmout_action:testaction:1</ocil:test_action_ref>
52264 ··········</ocil:actions>52252 ··········</ocil:actions>
52265 ········</ocil:questionnaire>52253 ········</ocil:questionnaire>
52266 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_gshadow_ocil:questionnaire:1">52254 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">
52267 ··········<ocil:title>Verify·User·Who·Owns·gshadow·File</ocil:title>52255 ··········<ocil:title>Verify·Owner·on·cron.monthly</ocil:title>
52268 ··········<ocil:actions>52256 ··········<ocil:actions>
52269 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_gshadow_action:testaction:1</ocil:test_action_ref>52257 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>
52270 ··········</ocil:actions>52258 ··········</ocil:actions>
52271 ········</ocil:questionnaire>52259 ········</ocil:questionnaire>
52272 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ucredit_ocil:questionnaire:1"> 
52273 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Uppercase·Characters</ocil:title>52260 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1">
 52261 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title>
52274 ··········<ocil:actions>52262 ··········<ocil:actions>
52275 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ucredit_action:testaction:1</ocil:test_action_ref>52263 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>
52276 ··········</ocil:actions>52264 ··········</ocil:actions>
52277 ········</ocil:questionnaire>52265 ········</ocil:questionnaire>
52278 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_sctp_disabled_ocil:questionnaire:1">52266 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_hourly_ocil:questionnaire:1">
52279 ··········<ocil:title>Disable·SCTP·Support</ocil:title>52267 ··········<ocil:title>Verify·Owner·on·cron.hourly</ocil:title>
52280 ··········<ocil:actions>52268 ··········<ocil:actions>
52281 ············<ocil:test_action_ref>ocil:ssg-kernel_module_sctp_disabled_action:testaction:1</ocil:test_action_ref>52269 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_hourly_action:testaction:1</ocil:test_action_ref>
52282 ··········</ocil:actions>52270 ··········</ocil:actions>
52283 ········</ocil:questionnaire>52271 ········</ocil:questionnaire>
52284 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fsetxattr_ocil:questionnaire:1"> 
52285 ··········<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fsetxattr</ocil:title>52272 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_weekly_ocil:questionnaire:1">
 52273 ··········<ocil:title>Verify·Group·Who·Owns·cron.weekly</ocil:title>
52286 ··········<ocil:actions>52274 ··········<ocil:actions>
52287 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fsetxattr_action:testaction:1</ocil:test_action_ref>52275 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_weekly_action:testaction:1</ocil:test_action_ref>
52288 ··········</ocil:actions>52276 ··········</ocil:actions>
52289 ········</ocil:questionnaire>52277 ········</ocil:questionnaire>
52290 ········<ocil:questionnaire·id="ocil:ssg-package_telnet-server_removed_ocil:questionnaire:1">52278 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_insmod_ocil:questionnaire:1">
52291 ··········<ocil:title>Uninstall·telnet-server·Package</ocil:title>52279 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·insmod</ocil:title>
52292 ··········<ocil:actions>52280 ··········<ocil:actions>
52293 ············<ocil:test_action_ref>ocil:ssg-package_telnet-server_removed_action:testaction:1</ocil:test_action_ref>52281 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_insmod_action:testaction:1</ocil:test_action_ref>
52294 ··········</ocil:actions>52282 ··········</ocil:actions>
52295 ········</ocil:questionnaire>52283 ········</ocil:questionnaire>
52296 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_logging_configured_ocil:questionnaire:1">52284 ········<ocil:questionnaire·id="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1">
52297 ··········<ocil:title>Ensure·logging·is·configured</ocil:title>52285 ··········<ocil:title>Verify·firewalld·Enabled</ocil:title>
52298 ··········<ocil:actions>52286 ··········<ocil:actions>
52299 ············<ocil:test_action_ref>ocil:ssg-rsyslog_logging_configured_action:testaction:1</ocil:test_action_ref>52287 ············<ocil:test_action_ref>ocil:ssg-service_firewalld_enabled_action:testaction:1</ocil:test_action_ref>
52300 ··········</ocil:actions>52288 ··········</ocil:actions>
52301 ········</ocil:questionnaire>52289 ········</ocil:questionnaire>
52302 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fremovexattr_ocil:questionnaire:1">52290 ········<ocil:questionnaire·id="ocil:ssg-package_httpd_removed_ocil:questionnaire:1">
52303 ··········<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fremovexattr</ocil:title>52291 ··········<ocil:title>Uninstall·httpd·Package</ocil:title>
52304 ··········<ocil:actions>52292 ··········<ocil:actions>
52305 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>52293 ············<ocil:test_action_ref>ocil:ssg-package_httpd_removed_action:testaction:1</ocil:test_action_ref>
52306 ··········</ocil:actions>52294 ··········</ocil:actions>
52307 ········</ocil:questionnaire>52295 ········</ocil:questionnaire>
Max diff block lines reached; 562044/573602 bytes (97.99%) of diff not shown.
532 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ocil.xml
532 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ocil.xml
Ordering differences only
    
Offset 3, 4501 lines modifiedOffset 3, 4577 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-accounts_tmout_ocil:questionnaire:1">
 11 ······<ocil:title>Set·Interactive·Session·Timeout</ocil:title>
11 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1"> 
17 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-set_nftables_loopback_traffic_ocil:questionnaire:1"> 
23 ······<ocil:title>Set·nftables·Configuration·for·Loopback·Traffic</ocil:title> 
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-set_nftables_loopback_traffic_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-accounts_tmout_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_gshadow_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">
29 ······<ocil:title>Verify·User·Who·Owns·gshadow·File</ocil:title>17 ······<ocil:title>Verify·Owner·on·cron.monthly</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_gshadow_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ucredit_ocil:questionnaire:1"> 
35 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Uppercase·Characters</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1">
 23 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ucredit_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_sctp_disabled_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_hourly_ocil:questionnaire:1">
41 ······<ocil:title>Disable·SCTP·Support</ocil:title>29 ······<ocil:title>Verify·Owner·on·cron.hourly</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kernel_module_sctp_disabled_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_hourly_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fsetxattr_ocil:questionnaire:1"> 
47 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fsetxattr</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_weekly_ocil:questionnaire:1">
 35 ······<ocil:title>Verify·Group·Who·Owns·cron.weekly</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fsetxattr_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_weekly_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-package_telnet-server_removed_ocil:questionnaire:1"> 
53 ······<ocil:title>Uninstall·telnet-server·Package</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_insmod_ocil:questionnaire:1">
 41 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·insmod</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-package_telnet-server_removed_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_insmod_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_logging_configured_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·logging·is·configured</ocil:title>47 ······<ocil:title>Verify·firewalld·Enabled</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-rsyslog_logging_configured_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-service_firewalld_enabled_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fremovexattr_ocil:questionnaire:1"> 
65 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fremovexattr</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-package_httpd_removed_ocil:questionnaire:1">
 53 ······<ocil:title>Uninstall·httpd·Package</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-package_httpd_removed_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
71 ······<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>59 ······<ocil:title>Disable·X11·Forwarding</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-package_aide_installed_ocil:questionnaire:1">
77 ······<ocil:title>Set·SSH·MaxSessions·limit</ocil:title>65 ······<ocil:title>Install·AIDE</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_sessions_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-no_netrc_files_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1">
83 ······<ocil:title>Verify·No·netrc·Files·Exist</ocil:title>71 ······<ocil:title>Deactivate·Wireless·Network·Interfaces</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-no_netrc_files_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1"> 
89 ······<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1">
 77 ······<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-aide_build_database_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1">
95 ······<ocil:title>Build·and·Test·AIDE·Database</ocil:title>83 ······<ocil:title>Verify·Permissions·on·/etc/at.allow·file</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-aide_build_database_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_at_allow_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_weekly_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-set_loopback_traffic_ocil:questionnaire:1">
101 ······<ocil:title>Verify·Group·Who·Owns·cron.weekly</ocil:title>89 ······<ocil:title>Set·configuration·for·loopback·traffic</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_weekly_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-set_loopback_traffic_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_chown_ocil:questionnaire:1"> 
107 ······<ocil:title>Record·Successful·Ownership·Changes·to·Files·-·chown</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_ocil:questionnaire:1">
 95 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv6·Interfaces</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_chown_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·LDAP·client·is·not·installed</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1">
 101 ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-package_openldap-clients_removed_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_unlink_ocil:questionnaire:1">
119 ······<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>107 ······<ocil:title>Record·Successful·Delete·Attempts·to·Files·-·unlink</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_unlink_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 532503/544258 bytes (97.84%) of diff not shown.
680 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds.xml
680 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:15.0">28 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:15.0">
29 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·15.0</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·15.0</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap15:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap15:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.1">32 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.1">
33 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.1</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.1</cpe-dict:title>
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.3">40 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.3">
41 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.3</cpe-dict:title>41 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.3</cpe-dict:title>
42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap42:def:1</cpe-dict:check>42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap42:def:1</cpe-dict:check>
43 ······</cpe-dict:cpe-item>43 ······</cpe-dict:cpe-item>
44 ····</cpe-dict:cpe-list>44 ····</cpe-dict:cpe-list>
45 ··</ds:component>45 ··</ds:component>
46 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-xccdf.xml"·timestamp="2025-02-28T20:08:00">46 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-xccdf.xml"·timestamp="2025-03-01T22:08:00">
47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENSUSE"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENSUSE"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openSUSE</xccdf-1.2:title>49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openSUSE</xccdf-1.2:title>
50 ······<xccdf-1.2:description>50 ······<xccdf-1.2:description>
51 ········This·guide·presents·a·catalog·of·security-relevant51 ········This·guide·presents·a·catalog·of·security-relevant
52 configuration·settings·for·openSUSE.·It·is·a·rendering·of52 configuration·settings·for·openSUSE.·It·is·a·rendering·of
53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 41119, 15 lines modifiedOffset 41119, 15 lines modified
41119 ··············<xccdf-1.2:check-content-ref·href="ssg-opensuse-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>41119 ··············<xccdf-1.2:check-content-ref·href="ssg-opensuse-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
41120 ············</xccdf-1.2:check>41120 ············</xccdf-1.2:check>
41121 ··········</xccdf-1.2:Rule>41121 ··········</xccdf-1.2:Rule>
41122 ········</xccdf-1.2:Group>41122 ········</xccdf-1.2:Group>
41123 ······</xccdf-1.2:Group>41123 ······</xccdf-1.2:Group>
41124 ····</xccdf-1.2:Benchmark>41124 ····</xccdf-1.2:Benchmark>
41125 ··</ds:component>41125 ··</ds:component>
41126 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-oval.xml"·timestamp="2025-02-28T20:08:00">41126 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-oval.xml"·timestamp="2025-03-01T22:08:00">
41127 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">41127 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
41128 ······<oval-def:generator>41128 ······<oval-def:generator>
41129 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>41129 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
41130 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>41130 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
41131 ········<oval:schema_version>5.11</oval:schema_version>41131 ········<oval:schema_version>5.11</oval:schema_version>
41132 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>41132 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
41133 ······</oval-def:generator>41133 ······</oval-def:generator>
Offset 56631, 2714 lines modifiedOffset 56631, 2714 lines modified
56631 ············</oval-def:arithmetic>56631 ············</oval-def:arithmetic>
56632 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>56632 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
56633 ··········</oval-def:arithmetic>56633 ··········</oval-def:arithmetic>
56634 ········</oval-def:local_variable>56634 ········</oval-def:local_variable>
56635 ······</oval-def:variables>56635 ······</oval-def:variables>
56636 ····</oval-def:oval_definitions>56636 ····</oval-def:oval_definitions>
56637 ··</ds:component>56637 ··</ds:component>
56638 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-ocil.xml"·timestamp="2025-02-28T20:08:00">56638 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-ocil.xml"·timestamp="2025-03-01T22:08:00">
56639 ····<ocil:ocil>56639 ····<ocil:ocil>
56640 ······<ocil:generator>56640 ······<ocil:generator>
56641 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>56641 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
56642 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>56642 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
56643 ········<ocil:schema_version>2.0</ocil:schema_version>56643 ········<ocil:schema_version>2.0</ocil:schema_version>
56644 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>56644 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
56645 ······</ocil:generator>56645 ······</ocil:generator>
56646 ······<ocil:questionnaires>56646 ······<ocil:questionnaires>
56647 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1"> 
56648 ··········<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Root</ocil:title>56647 ········<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">
 56648 ··········<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>
56649 ··········<ocil:actions>56649 ··········<ocil:actions>
56650 ············<ocil:test_action_ref>ocil:ssg-file_ownership_audit_configuration_action:testaction:1</ocil:test_action_ref>56650 ············<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>
56651 ··········</ocil:actions>56651 ··········</ocil:actions>
56652 ········</ocil:questionnaire>56652 ········</ocil:questionnaire>
56653 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1">56653 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_notifiers_ocil:questionnaire:1">
56654 ··········<ocil:title>Enable·checks·on·scatter-gather·(SG)·table·operations</ocil:title>56654 ··········<ocil:title>Enable·checks·on·notifier·call·chains</ocil:title>
56655 ··········<ocil:actions>56655 ··········<ocil:actions>
56656 ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_sg_action:testaction:1</ocil:test_action_ref>56656 ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_notifiers_action:testaction:1</ocil:test_action_ref>
56657 ··········</ocil:actions>56657 ··········</ocil:actions>
56658 ········</ocil:questionnaire>56658 ········</ocil:questionnaire>
56659 ········<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1">56659 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">
56660 ··········<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>56660 ··········<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title>
56661 ··········<ocil:actions>56661 ··········<ocil:actions>
56662 ············<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>56662 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref>
56663 ··········</ocil:actions>56663 ··········</ocil:actions>
56664 ········</ocil:questionnaire>56664 ········</ocil:questionnaire>
56665 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1"> 
56666 ··········<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>56665 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_syslog_ocil:questionnaire:1">
 56666 ··········<ocil:title>Verify·Permissions·on·/var/log/syslog·File</ocil:title>
56667 ··········<ocil:actions>56667 ··········<ocil:actions>
56668 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>56668 ············<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_syslog_action:testaction:1</ocil:test_action_ref>
56669 ··········</ocil:actions>56669 ··········</ocil:actions>
56670 ········</ocil:questionnaire>56670 ········</ocil:questionnaire>
56671 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chmod_ocil:questionnaire:1">56671 ········<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">
56672 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chmod</ocil:title>56672 ··········<ocil:title>Enable·auditd·Service</ocil:title>
56673 ··········<ocil:actions>56673 ··········<ocil:actions>
56674 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chmod_action:testaction:1</ocil:test_action_ref>56674 ············<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>
56675 ··········</ocil:actions>56675 ··········</ocil:actions>
56676 ········</ocil:questionnaire>56676 ········</ocil:questionnaire>
56677 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">56677 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1">
56678 ··········<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>56678 ··········<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title>
56679 ··········<ocil:actions>56679 ··········<ocil:actions>
56680 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>56680 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
56681 ··········</ocil:actions>56681 ··········</ocil:actions>
56682 ········</ocil:questionnaire>56682 ········</ocil:questionnaire>
56683 ········<ocil:questionnaire·id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1">56683 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">
56684 ··········<ocil:title>Ensure·the·Logon·Failure·Delay·is·Set·Correctly·in·login.defs</ocil:title>56684 ··········<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
56685 ··········<ocil:actions>56685 ··········<ocil:actions>
56686 ············<ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>56686 ············<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
56687 ··········</ocil:actions>56687 ··········</ocil:actions>
56688 ········</ocil:questionnaire>56688 ········</ocil:questionnaire>
56689 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1">56689 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1">
56690 ··········<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title>56690 ··········<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Root</ocil:title>
56691 ··········<ocil:actions>56691 ··········<ocil:actions>
56692 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>56692 ············<ocil:test_action_ref>ocil:ssg-file_ownership_audit_configuration_action:testaction:1</ocil:test_action_ref>
56693 ··········</ocil:actions>56693 ··········</ocil:actions>
56694 ········</ocil:questionnaire>56694 ········</ocil:questionnaire>
56695 ········<ocil:questionnaire·id="ocil:ssg-package_audit_installed_ocil:questionnaire:1">56695 ········<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">
56696 ··········<ocil:title>Ensure·the·audit·Subsystem·is·Installed</ocil:title>56696 ··········<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>
56697 ··········<ocil:actions>56697 ··········<ocil:actions>
56698 ············<ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>56698 ············<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>
56699 ··········</ocil:actions>56699 ··········</ocil:actions>
56700 ········</ocil:questionnaire>56700 ········</ocil:questionnaire>
56701 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1">56701 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1">
56702 ··········<ocil:title>Verify·Permissions·on·shadow·File</ocil:title>56702 ··········<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·by·Default</ocil:title>
56703 ··········<ocil:actions>56703 ··········<ocil:actions>
56704 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shadow_action:testaction:1</ocil:test_action_ref>56704 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_action:testaction:1</ocil:test_action_ref>
56705 ··········</ocil:actions>56705 ··········</ocil:actions>
56706 ········</ocil:questionnaire>56706 ········</ocil:questionnaire>
56707 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">56707 ········<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
Max diff block lines reached; 683761/695719 bytes (98.28%) of diff not shown.
646 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ocil.xml
646 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ocil.xml
Ordering differences only
    
Offset 3, 2705 lines modifiedOffset 3, 2705 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1"> 
11 ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Root</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-file_ownership_audit_configuration_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_notifiers_ocil:questionnaire:1">
17 ······<ocil:title>Enable·checks·on·scatter-gather·(SG)·table·operations</ocil:title>17 ······<ocil:title>Enable·checks·on·notifier·call·chains</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_sg_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_notifiers_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">
23 ······<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>23 ······<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1"> 
29 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_syslog_ocil:questionnaire:1">
 29 ······<ocil:title>Verify·Permissions·on·/var/log/syslog·File</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_syslog_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chmod_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">
35 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chmod</ocil:title>35 ······<ocil:title>Enable·auditd·Service</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chmod_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1">
41 ······<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>41 ······<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·the·Logon·Failure·Delay·is·Set·Correctly·in·login.defs</ocil:title>47 ······<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1">
53 ······<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title>53 ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Root</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_ownership_audit_configuration_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-package_audit_installed_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·the·audit·Subsystem·is·Installed</ocil:title>59 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1">
65 ······<ocil:title>Verify·Permissions·on·shadow·File</ocil:title>65 ······<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·by·Default</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shadow_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
71 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>71 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nodev_ocil:questionnaire:1">
77 ······<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>77 ······<ocil:title>Add·nodev·Option·to·/dev/shm</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nodev_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">
83 ······<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·for·All·IPv4·Interfaces</ocil:title>83 ······<ocil:title>The·Chrony·package·is·installed</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_ocil:questionnaire:1">
89 ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>89 ······<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_binary_dirs_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1">
95 ······<ocil:title>Verify·that·System·Executables·Have·Root·Ownership</ocil:title>95 ······<ocil:title>Set·SSH·Client·Alive·Count·Max·to·zero</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_0_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-no_all_squash_exports_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title>101 ······<ocil:title>Ensure·All-Squashing·Disabled·On·All·Exports</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-no_all_squash_exports_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-chronyd_server_directive_ocil:questionnaire:1">
107 ······<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>107 ······<ocil:title>Ensure·Chrony·is·only·configured·with·the·server·directive</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-chronyd_server_directive_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1"> 
113 ······<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">
 113 ······<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">
119 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>119 ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount2_ocil:questionnaire:1"> 
125 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount2</ocil:title>124 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">
 125 ······<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>
Max diff block lines reached; 648285/660970 bytes (98.08%) of diff not shown.
1.62 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds.xml
1.62 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux_coreos:4">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux_coreos:4">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·CoreOS·4</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·CoreOS·4</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml">oval:ssg-installed_OS_is_rhcos4:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml">oval:ssg-installed_OS_is_rhcos4:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHCOS-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHCOS-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Red·Hat·Enterprise·Linux·CoreOS·4.·It·is·a·rendering·of40 configuration·settings·for·Red·Hat·Enterprise·Linux·CoreOS·4.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 321, 23 lines modifiedOffset 321, 23 lines modified
321 ··········</cpe-lang:logical-test>321 ··········</cpe-lang:logical-test>
322 ········</cpe-lang:platform>322 ········</cpe-lang:platform>
323 ········<cpe-lang:platform·id="package_bash">323 ········<cpe-lang:platform·id="package_bash">
324 ··········<cpe-lang:logical-test·operator="AND"·negate="false">324 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
325 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>325 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
326 ··········</cpe-lang:logical-test>326 ··········</cpe-lang:logical-test>
327 ········</cpe-lang:platform>327 ········</cpe-lang:platform>
328 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">328 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
329 ··········<cpe-lang:logical-test·operator="AND"·negate="false">329 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
330 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>330 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
331 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
332 ··········</cpe-lang:logical-test>331 ··········</cpe-lang:logical-test>
333 ········</cpe-lang:platform>332 ········</cpe-lang:platform>
334 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">333 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
335 ··········<cpe-lang:logical-test·operator="AND"·negate="false">334 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
336 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>335 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 336 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
337 ··········</cpe-lang:logical-test>337 ··········</cpe-lang:logical-test>
338 ········</cpe-lang:platform>338 ········</cpe-lang:platform>
339 ········<cpe-lang:platform·id="package_tmux">339 ········<cpe-lang:platform·id="package_tmux">
340 ··········<cpe-lang:logical-test·operator="AND"·negate="false">340 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
341 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_tmux:def:1"/>341 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_tmux:def:1"/>
342 ··········</cpe-lang:logical-test>342 ··········</cpe-lang:logical-test>
343 ········</cpe-lang:platform>343 ········</cpe-lang:platform>
Offset 66389, 15 lines modifiedOffset 66389, 15 lines modified
66389 ··············<xccdf-1.2:check-content-ref·href="ssg-rhcos4-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>66389 ··············<xccdf-1.2:check-content-ref·href="ssg-rhcos4-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
66390 ············</xccdf-1.2:check>66390 ············</xccdf-1.2:check>
66391 ··········</xccdf-1.2:Rule>66391 ··········</xccdf-1.2:Rule>
66392 ········</xccdf-1.2:Group>66392 ········</xccdf-1.2:Group>
66393 ······</xccdf-1.2:Group>66393 ······</xccdf-1.2:Group>
66394 ····</xccdf-1.2:Benchmark>66394 ····</xccdf-1.2:Benchmark>
66395 ··</ds:component>66395 ··</ds:component>
66396 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-oval.xml"·timestamp="2025-02-28T20:08:00">66396 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-oval.xml"·timestamp="2025-03-01T22:08:00">
66397 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">66397 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
66398 ······<oval-def:generator>66398 ······<oval-def:generator>
66399 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>66399 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
66400 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>66400 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
66401 ········<oval:schema_version>5.11</oval:schema_version>66401 ········<oval:schema_version>5.11</oval:schema_version>
66402 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>66402 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
66403 ······</oval-def:generator>66403 ······</oval-def:generator>
Offset 104700, 8240 lines modifiedOffset 104700, 8240 lines modified
104700 ············</oval-def:arithmetic>104700 ············</oval-def:arithmetic>
104701 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>104701 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
104702 ··········</oval-def:arithmetic>104702 ··········</oval-def:arithmetic>
104703 ········</oval-def:local_variable>104703 ········</oval-def:local_variable>
104704 ······</oval-def:variables>104704 ······</oval-def:variables>
104705 ····</oval-def:oval_definitions>104705 ····</oval-def:oval_definitions>
104706 ··</ds:component>104706 ··</ds:component>
104707 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"·timestamp="2025-02-28T20:08:00">104707 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"·timestamp="2025-03-01T22:08:00">
104708 ····<ocil:ocil>104708 ····<ocil:ocil>
104709 ······<ocil:generator>104709 ······<ocil:generator>
104710 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>104710 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
104711 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>104711 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
104712 ········<ocil:schema_version>2.0</ocil:schema_version>104712 ········<ocil:schema_version>2.0</ocil:schema_version>
104713 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>104713 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
104714 ······</ocil:generator>104714 ······</ocil:generator>
104715 ······<ocil:questionnaires>104715 ······<ocil:questionnaires>
104716 ········<ocil:questionnaire·id="ocil:ssg-package_postfix_installed_ocil:questionnaire:1"> 
104717 ··········<ocil:title>The·Postfix·package·is·installed</ocil:title>104716 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_chown_ocil:questionnaire:1">
 104717 ··········<ocil:title>Record·Unsuccessful·Ownership·Changes·to·Files·-·chown</ocil:title>
104718 ··········<ocil:actions>104718 ··········<ocil:actions>
104719 ············<ocil:test_action_ref>ocil:ssg-package_postfix_installed_action:testaction:1</ocil:test_action_ref>104719 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_chown_action:testaction:1</ocil:test_action_ref>
104720 ··········</ocil:actions>104720 ··········</ocil:actions>
104721 ········</ocil:questionnaire>104721 ········</ocil:questionnaire>
104722 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_gshadow_ocil:questionnaire:1"> 
104723 ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/gshadow</ocil:title>104722 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_sestatus_conf_ocil:questionnaire:1">
 104723 ··········<ocil:title>Verify·User·Who·Owns·/etc/sestatus.conf·File</ocil:title>
104724 ··········<ocil:actions>104724 ··········<ocil:actions>
104725 ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_gshadow_action:testaction:1</ocil:test_action_ref>104725 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref>
104726 ··········</ocil:actions>104726 ··········</ocil:actions>
104727 ········</ocil:questionnaire>104727 ········</ocil:questionnaire>
104728 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_group_ocil:questionnaire:1">104728 ········<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1">
104729 ··········<ocil:title>Verify·Group·Who·Owns·group·File</ocil:title>104729 ··········<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>
104730 ··········<ocil:actions>104730 ··········<ocil:actions>
104731 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_group_action:testaction:1</ocil:test_action_ref>104731 ············<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>
104732 ··········</ocil:actions>104732 ··········</ocil:actions>
104733 ········</ocil:questionnaire>104733 ········</ocil:questionnaire>
104734 ········<ocil:questionnaire·id="ocil:ssg-file_owner_efi_grub2_cfg_ocil:questionnaire:1">104734 ········<ocil:questionnaire·id="ocil:ssg-package_fapolicyd_installed_ocil:questionnaire:1">
104735 ··········<ocil:title>Verify·the·UEFI·Boot·Loader·grub.cfg·User·Ownership</ocil:title>104735 ··········<ocil:title>Install·fapolicyd·Package</ocil:title>
104736 ··········<ocil:actions>104736 ··········<ocil:actions>
104737 ············<ocil:test_action_ref>ocil:ssg-file_owner_efi_grub2_cfg_action:testaction:1</ocil:test_action_ref>104737 ············<ocil:test_action_ref>ocil:ssg-package_fapolicyd_installed_action:testaction:1</ocil:test_action_ref>
104738 ··········</ocil:actions>104738 ··········</ocil:actions>
104739 ········</ocil:questionnaire>104739 ········</ocil:questionnaire>
104740 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1"> 
104741 ··········<ocil:title>Verify·Group·Who·Owns·/var/log/messages·File</ocil:title>104740 ········<ocil:questionnaire·id="ocil:ssg-ensure_redhat_gpgkey_installed_ocil:questionnaire:1">
 104741 ··········<ocil:title>Ensure·Red·Hat·GPG·Key·Installed</ocil:title>
104742 ··········<ocil:actions>104742 ··········<ocil:actions>
104743 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_messages_action:testaction:1</ocil:test_action_ref>104743 ············<ocil:test_action_ref>ocil:ssg-ensure_redhat_gpgkey_installed_action:testaction:1</ocil:test_action_ref>
104744 ··········</ocil:actions>104744 ··········</ocil:actions>
104745 ········</ocil:questionnaire>104745 ········</ocil:questionnaire>
104746 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_issue_net_ocil:questionnaire:1">104746 ········<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1">
104747 ··········<ocil:title>Verify·ownership·of·System·Login·Banner·for·Remote·Connections</ocil:title>104747 ··········<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title>
104748 ··········<ocil:actions>104748 ··········<ocil:actions>
104749 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_issue_net_action:testaction:1</ocil:test_action_ref>104749 ············<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref>
104750 ··········</ocil:actions>104750 ··········</ocil:actions>
104751 ········</ocil:questionnaire>104751 ········</ocil:questionnaire>
104752 ········<ocil:questionnaire·id="ocil:ssg-ssh_client_rekey_limit_ocil:questionnaire:1">104752 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1">
104753 ··········<ocil:title>Configure·session·renegotiation·for·SSH·client</ocil:title>104753 ··········<ocil:title>Disable·the·IPv6·protocol</ocil:title>
104754 ··········<ocil:actions>104754 ··········<ocil:actions>
104755 ············<ocil:test_action_ref>ocil:ssg-ssh_client_rekey_limit_action:testaction:1</ocil:test_action_ref>104755 ············<ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref>
104756 ··········</ocil:actions>104756 ··········</ocil:actions>
104757 ········</ocil:questionnaire>104757 ········</ocil:questionnaire>
104758 ········<ocil:questionnaire·id="ocil:ssg-mount_option_noexec_removable_partitions_ocil:questionnaire:1"> 
Max diff block lines reached; 1689219/1701139 bytes (99.30%) of diff not shown.
1.55 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ocil.xml
1.55 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ocil.xml
Ordering differences only
    
Offset 3, 8231 lines modifiedOffset 3, 8231 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-package_postfix_installed_ocil:questionnaire:1"> 
11 ······<ocil:title>The·Postfix·package·is·installed</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_chown_ocil:questionnaire:1">
 11 ······<ocil:title>Record·Unsuccessful·Ownership·Changes·to·Files·-·chown</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-package_postfix_installed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_chown_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_gshadow_ocil:questionnaire:1"> 
17 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/gshadow</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_sestatus_conf_ocil:questionnaire:1">
 17 ······<ocil:title>Verify·User·Who·Owns·/etc/sestatus.conf·File</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_gshadow_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_group_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1">
23 ······<ocil:title>Verify·Group·Who·Owns·group·File</ocil:title>23 ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_group_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_efi_grub2_cfg_ocil:questionnaire:1"> 
29 ······<ocil:title>Verify·the·UEFI·Boot·Loader·grub.cfg·User·Ownership</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-package_fapolicyd_installed_ocil:questionnaire:1">
 29 ······<ocil:title>Install·fapolicyd·Package</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_owner_efi_grub2_cfg_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-package_fapolicyd_installed_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1"> 
35 ······<ocil:title>Verify·Group·Who·Owns·/var/log/messages·File</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-ensure_redhat_gpgkey_installed_ocil:questionnaire:1">
 35 ······<ocil:title>Ensure·Red·Hat·GPG·Key·Installed</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_messages_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-ensure_redhat_gpgkey_installed_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_issue_net_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1">
41 ······<ocil:title>Verify·ownership·of·System·Login·Banner·for·Remote·Connections</ocil:title>41 ······<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_issue_net_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-ssh_client_rekey_limit_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1">
47 ······<ocil:title>Configure·session·renegotiation·for·SSH·client</ocil:title>47 ······<ocil:title>Disable·the·IPv6·protocol</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-ssh_client_rekey_limit_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-mount_option_noexec_removable_partitions_ocil:questionnaire:1"> 
53 ······<ocil:title>Add·noexec·Option·to·Removable·Media·Partitions</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_etc_passwd_open_ocil:questionnaire:1">
 53 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·via·open·syscall·-·/etc/passwd</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-mount_option_noexec_removable_partitions_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_etc_passwd_open_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-coreos_disable_interactive_boot_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-aide_build_database_ocil:questionnaire:1">
59 ······<ocil:title>Verify·that·Interactive·Boot·is·Disabled</ocil:title>59 ······<ocil:title>Build·and·Test·AIDE·Database</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-coreos_disable_interactive_boot_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-aide_build_database_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_ipsec_conf_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nosuid_ocil:questionnaire:1">
65 ······<ocil:title>Verify·Group·Who·Owns·/etc/ipsec.conf·File</ocil:title>65 ······<ocil:title>Add·nosuid·Option·to·/home</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_ipsec_conf_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nosuid_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-package_libselinux_installed_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1">
71 ······<ocil:title>Install·libselinux·Package</ocil:title>71 ······<ocil:title>Disable·kernel·debugfs</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-package_libselinux_installed_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-coredump_disabled_ocil:questionnaire:1"> 
77 ······<ocil:title>Disable·acquiring,·saving,·and·processing·core·dumps</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1">
 77 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-service_systemd-coredump_disabled_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_mount_nfs_ocil:questionnaire:1"> 
83 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·mount.nfs</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_ocil:questionnaire:1">
 83 ······<ocil:title>Configure·System·to·Forward·All·Mail·From·Postmaster·to·The·Root·Account</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_mount_nfs_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_postmaster_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_maxstartups_ocil:questionnaire:1">
89 ······<ocil:title>Disable·IPv6·Addressing·on·All·IPv6·Interfaces</ocil:title>89 ······<ocil:title>Ensure·SSH·MaxStartups·is·configured</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sshd_set_maxstartups_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1"> 
95 ······<ocil:title>Configure·BIND·to·use·System·Crypto·Policy</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_ipsec_secrets_ocil:questionnaire:1">
 95 ······<ocil:title>Verify·Group·Who·Owns·/etc/ipsec.secrets·File</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-configure_bind_crypto_policy_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_ipsec_secrets_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-auditd_write_logs_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_chsh_ocil:questionnaire:1">
101 ······<ocil:title>Write·Audit·Logs·to·the·Disk</ocil:title>101 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·chsh</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-auditd_write_logs_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_chsh_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_stig_ocil:questionnaire:1">
107 ······<ocil:title>Disable·/dev/kmem·virtual·device·support</ocil:title>107 ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_devkmem_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_stig_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_creat_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1">
113 ······<ocil:title>Record·Unsuccessful·Creation·Attempts·to·Files·-·openat·O_CREAT</ocil:title>113 ······<ocil:title>Make·the·auditd·Configuration·Immutable</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_creat_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1"> 
119 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_ocil:questionnaire:1">
 119 ······<ocil:title>Enable·Kernel·Parameter·to·Ignore·Bogus·ICMP·Error·Responses·on·IPv4·Interfaces</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
Max diff block lines reached; 1616213/1628774 bytes (99.23%) of diff not shown.
2.47 KB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-xccdf.xml
2.37 KB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-xccdf.xml
Ordering differences only
    
Offset 288, 23 lines modifiedOffset 288, 23 lines modified
288 ······</cpe-lang:logical-test>288 ······</cpe-lang:logical-test>
289 ····</cpe-lang:platform>289 ····</cpe-lang:platform>
290 ····<cpe-lang:platform·id="package_bash">290 ····<cpe-lang:platform·id="package_bash">
291 ······<cpe-lang:logical-test·operator="AND"·negate="false">291 ······<cpe-lang:logical-test·operator="AND"·negate="false">
292 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>292 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
293 ······</cpe-lang:logical-test>293 ······</cpe-lang:logical-test>
294 ····</cpe-lang:platform>294 ····</cpe-lang:platform>
295 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">295 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
296 ······<cpe-lang:logical-test·operator="AND"·negate="false">296 ······<cpe-lang:logical-test·operator="AND"·negate="false">
297 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>297 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
298 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
299 ······</cpe-lang:logical-test>298 ······</cpe-lang:logical-test>
300 ····</cpe-lang:platform>299 ····</cpe-lang:platform>
301 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">300 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
302 ······<cpe-lang:logical-test·operator="AND"·negate="false">301 ······<cpe-lang:logical-test·operator="AND"·negate="false">
303 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>302 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 303 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
304 ······</cpe-lang:logical-test>304 ······</cpe-lang:logical-test>
305 ····</cpe-lang:platform>305 ····</cpe-lang:platform>
306 ····<cpe-lang:platform·id="package_tmux">306 ····<cpe-lang:platform·id="package_tmux">
307 ······<cpe-lang:logical-test·operator="AND"·negate="false">307 ······<cpe-lang:logical-test·operator="AND"·negate="false">
308 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_tmux:def:1"/>308 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_tmux:def:1"/>
309 ······</cpe-lang:logical-test>309 ······</cpe-lang:logical-test>
310 ····</cpe-lang:platform>310 ····</cpe-lang:platform>
2.15 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ds.xml
2.15 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of40 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 312, 23 lines modifiedOffset 312, 23 lines modified
312 ··········</cpe-lang:logical-test>312 ··········</cpe-lang:logical-test>
313 ········</cpe-lang:platform>313 ········</cpe-lang:platform>
314 ········<cpe-lang:platform·id="package_bash">314 ········<cpe-lang:platform·id="package_bash">
315 ··········<cpe-lang:logical-test·operator="AND"·negate="false">315 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
316 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>316 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
317 ··········</cpe-lang:logical-test>317 ··········</cpe-lang:logical-test>
318 ········</cpe-lang:platform>318 ········</cpe-lang:platform>
319 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">319 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
320 ··········<cpe-lang:logical-test·operator="AND"·negate="false">320 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
321 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>321 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
322 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
323 ··········</cpe-lang:logical-test>322 ··········</cpe-lang:logical-test>
324 ········</cpe-lang:platform>323 ········</cpe-lang:platform>
325 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">324 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
326 ··········<cpe-lang:logical-test·operator="AND"·negate="false">325 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
327 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>326 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 327 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
328 ··········</cpe-lang:logical-test>328 ··········</cpe-lang:logical-test>
329 ········</cpe-lang:platform>329 ········</cpe-lang:platform>
330 ········<cpe-lang:platform·id="not_s390x_arch">330 ········<cpe-lang:platform·id="not_s390x_arch">
331 ··········<cpe-lang:logical-test·operator="AND"·negate="false">331 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
332 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>332 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
333 ··········</cpe-lang:logical-test>333 ··········</cpe-lang:logical-test>
334 ········</cpe-lang:platform>334 ········</cpe-lang:platform>
Offset 216676, 15 lines modifiedOffset 216676, 15 lines modified
216676 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/>216676 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/>
216677 ············</xccdf-1.2:check>216677 ············</xccdf-1.2:check>
216678 ··········</xccdf-1.2:Rule>216678 ··········</xccdf-1.2:Rule>
216679 ········</xccdf-1.2:Group>216679 ········</xccdf-1.2:Group>
216680 ······</xccdf-1.2:Group>216680 ······</xccdf-1.2:Group>
216681 ····</xccdf-1.2:Benchmark>216681 ····</xccdf-1.2:Benchmark>
216682 ··</ds:component>216682 ··</ds:component>
216683 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-02-28T20:08:00">216683 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-03-01T22:08:00">
216684 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">216684 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
216685 ······<oval-def:generator>216685 ······<oval-def:generator>
216686 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>216686 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
216687 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>216687 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
216688 ········<oval:schema_version>5.11</oval:schema_version>216688 ········<oval:schema_version>5.11</oval:schema_version>
216689 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>216689 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
216690 ······</oval-def:generator>216690 ······</oval-def:generator>
Offset 266291, 13718 lines modifiedOffset 266291, 13907 lines modified
266291 ············</oval-def:arithmetic>266291 ············</oval-def:arithmetic>
266292 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>266292 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
266293 ··········</oval-def:arithmetic>266293 ··········</oval-def:arithmetic>
266294 ········</oval-def:local_variable>266294 ········</oval-def:local_variable>
266295 ······</oval-def:variables>266295 ······</oval-def:variables>
266296 ····</oval-def:oval_definitions>266296 ····</oval-def:oval_definitions>
266297 ··</ds:component>266297 ··</ds:component>
266298 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-02-28T20:08:00">266298 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-03-01T22:08:00">
266299 ····<ocil:ocil>266299 ····<ocil:ocil>
266300 ······<ocil:generator>266300 ······<ocil:generator>
266301 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>266301 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
266302 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>266302 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
266303 ········<ocil:schema_version>2.0</ocil:schema_version>266303 ········<ocil:schema_version>2.0</ocil:schema_version>
266304 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>266304 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
266305 ······</ocil:generator>266305 ······</ocil:generator>
266306 ······<ocil:questionnaires>266306 ······<ocil:questionnaires>
266307 ········<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">266307 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_set_max_life_root_ocil:questionnaire:1">
266308 ··········<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>266308 ··········<ocil:title>Set·Root·Account·Password·Maximum·Age</ocil:title>
266309 ··········<ocil:actions>266309 ··········<ocil:actions>
266310 ············<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>266310 ············<ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_root_action:testaction:1</ocil:test_action_ref>
266311 ··········</ocil:actions>266311 ··········</ocil:actions>
266312 ········</ocil:questionnaire>266312 ········</ocil:questionnaire>
266313 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">266313 ········<ocil:questionnaire·id="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1">
266314 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>266314 ··········<ocil:title>Configure·BIND·to·use·System·Crypto·Policy</ocil:title>
266315 ··········<ocil:actions>266315 ··········<ocil:actions>
266316 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>266316 ············<ocil:test_action_ref>ocil:ssg-configure_bind_crypto_policy_action:testaction:1</ocil:test_action_ref>
266317 ··········</ocil:actions>266317 ··········</ocil:actions>
266318 ········</ocil:questionnaire>266318 ········</ocil:questionnaire>
266319 ········<ocil:questionnaire·id="ocil:ssg-enable_ldap_client_ocil:questionnaire:1">266319 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_user_cfg_ocil:questionnaire:1">
266320 ··········<ocil:title>Enable·the·LDAP·Client·For·Use·in·Authconfig</ocil:title>266320 ··········<ocil:title>Verify·/boot/grub2/user.cfg·Permissions</ocil:title>
266321 ··········<ocil:actions>266321 ··········<ocil:actions>
266322 ············<ocil:test_action_ref>ocil:ssg-enable_ldap_client_action:testaction:1</ocil:test_action_ref>266322 ············<ocil:test_action_ref>ocil:ssg-file_permissions_user_cfg_action:testaction:1</ocil:test_action_ref>
266323 ··········</ocil:actions>266323 ··········</ocil:actions>
266324 ········</ocil:questionnaire>266324 ········</ocil:questionnaire>
266325 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_modules_disabled_ocil:questionnaire:1"> 
266326 ··········<ocil:title>Disable·loading·and·unloading·of·kernel·modules</ocil:title>266325 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_enforce_root_ocil:questionnaire:1">
 266326 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Enforce·for·root·User</ocil:title>
266327 ··········<ocil:actions>266327 ··········<ocil:actions>
266328 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_modules_disabled_action:testaction:1</ocil:test_action_ref>266328 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_enforce_root_action:testaction:1</ocil:test_action_ref>
266329 ··········</ocil:actions>266329 ··········</ocil:actions>
266330 ········</ocil:questionnaire>266330 ········</ocil:questionnaire>
266331 ········<ocil:questionnaire·id="ocil:ssg-mount_option_nosuid_removable_partitions_ocil:questionnaire:1">266331 ········<ocil:questionnaire·id="ocil:ssg-gid_passwd_group_same_ocil:questionnaire:1">
266332 ··········<ocil:title>Add·nosuid·Option·to·Removable·Media·Partitions</ocil:title>266332 ··········<ocil:title>All·GIDs·referenced·in·/etc/passwd·must·be·defined·in·/etc/group</ocil:title>
266333 ··········<ocil:actions>266333 ··········<ocil:actions>
266334 ············<ocil:test_action_ref>ocil:ssg-mount_option_nosuid_removable_partitions_action:testaction:1</ocil:test_action_ref>266334 ············<ocil:test_action_ref>ocil:ssg-gid_passwd_group_same_action:testaction:1</ocil:test_action_ref>
266335 ··········</ocil:actions>266335 ··········</ocil:actions>
266336 ········</ocil:questionnaire>266336 ········</ocil:questionnaire>
266337 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_pkexec_ocil:questionnaire:1">266337 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1">
266338 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·pkexec</ocil:title>266338 ··········<ocil:title>Set·SSH·MaxSessions·limit</ocil:title>
266339 ··········<ocil:actions>266339 ··········<ocil:actions>
266340 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_pkexec_action:testaction:1</ocil:test_action_ref>266340 ············<ocil:test_action_ref>ocil:ssg-sshd_set_max_sessions_action:testaction:1</ocil:test_action_ref>
266341 ··········</ocil:actions>266341 ··········</ocil:actions>
266342 ········</ocil:questionnaire>266342 ········</ocil:questionnaire>
266343 ········<ocil:questionnaire·id="ocil:ssg-grub2_disable_interactive_boot_ocil:questionnaire:1">266343 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1">
266344 ··········<ocil:title>Verify·that·Interactive·Boot·is·Disabled</ocil:title>266344 ··········<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title>
266345 ··········<ocil:actions>266345 ··········<ocil:actions>
266346 ············<ocil:test_action_ref>ocil:ssg-grub2_disable_interactive_boot_action:testaction:1</ocil:test_action_ref>266346 ············<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref>
266347 ··········</ocil:actions>266347 ··········</ocil:actions>
266348 ········</ocil:questionnaire>266348 ········</ocil:questionnaire>
266349 ········<ocil:questionnaire·id="ocil:ssg-chronyd_configure_pool_and_server_ocil:questionnaire:1">266349 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_login_banner_text_ocil:questionnaire:1">
266350 ··········<ocil:title>Chrony·Configure·Pool·and·Server</ocil:title>266350 ··········<ocil:title>Set·the·GNOME3·Login·Warning·Banner·Text</ocil:title>
266351 ··········<ocil:actions>266351 ··········<ocil:actions>
Max diff block lines reached; 2240747/2252992 bytes (99.46%) of diff not shown.
2.06 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ocil.xml
2.06 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ocil.xml
Ordering differences only
    
Offset 3, 13709 lines modifiedOffset 3, 13898 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_max_life_root_ocil:questionnaire:1">
11 ······<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>11 ······<ocil:title>Set·Root·Account·Password·Maximum·Age</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_root_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1">
17 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>17 ······<ocil:title>Configure·BIND·to·use·System·Crypto·Policy</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-configure_bind_crypto_policy_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-enable_ldap_client_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_user_cfg_ocil:questionnaire:1">
23 ······<ocil:title>Enable·the·LDAP·Client·For·Use·in·Authconfig</ocil:title>23 ······<ocil:title>Verify·/boot/grub2/user.cfg·Permissions</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-enable_ldap_client_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_user_cfg_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_modules_disabled_ocil:questionnaire:1"> 
29 ······<ocil:title>Disable·loading·and·unloading·of·kernel·modules</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_enforce_root_ocil:questionnaire:1">
 29 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Enforce·for·root·User</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_modules_disabled_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_enforce_root_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-mount_option_nosuid_removable_partitions_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-gid_passwd_group_same_ocil:questionnaire:1">
35 ······<ocil:title>Add·nosuid·Option·to·Removable·Media·Partitions</ocil:title>35 ······<ocil:title>All·GIDs·referenced·in·/etc/passwd·must·be·defined·in·/etc/group</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-mount_option_nosuid_removable_partitions_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-gid_passwd_group_same_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_pkexec_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·pkexec</ocil:title>41 ······<ocil:title>Set·SSH·MaxSessions·limit</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_pkexec_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_sessions_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-grub2_disable_interactive_boot_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1">
47 ······<ocil:title>Verify·that·Interactive·Boot·is·Disabled</ocil:title>47 ······<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-grub2_disable_interactive_boot_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-chronyd_configure_pool_and_server_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_login_banner_text_ocil:questionnaire:1">
53 ······<ocil:title>Chrony·Configure·Pool·and·Server</ocil:title>53 ······<ocil:title>Set·the·GNOME3·Login·Warning·Banner·Text</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-chronyd_configure_pool_and_server_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_login_banner_text_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_passwd_ocil:questionnaire:1"> 
59 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·passwd</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_ocil:questionnaire:1">
 59 ······<ocil:title>Configure·Auto·Configuration·on·All·IPv6·Interfaces</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_passwd_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_fortify_source_ocil:questionnaire:1">
65 ······<ocil:title>Enable·Kernel·Parameter·to·Log·Martian·Packets·on·all·IPv4·Interfaces</ocil:title>65 ······<ocil:title>Harden·common·str/mem·functions·against·buffer·overflows</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_fortify_source_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-zipl_init_on_alloc_argument_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_credentials_ocil:questionnaire:1">
71 ······<ocil:title>Configure·kernel·to·zero·out·memory·before·allocation·in·zIPL</ocil:title>71 ······<ocil:title>Enable·checks·on·credential·management</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-zipl_init_on_alloc_argument_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_credentials_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_force_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-audit_modify_failed_ppc64le_ocil:questionnaire:1">
77 ······<ocil:title>Require·modules·to·be·validly·signed</ocil:title>77 ······<ocil:title>Configure·auditing·of·unsuccessful·file·modifications·(ppc64le)</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_force_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_modify_failed_ppc64le_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-audit_module_load_ppc64le_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·that·/etc/at.deny·does·not·exist</ocil:title>83 ······<ocil:title>Configure·auditing·of·loading·and·unloading·of·kernel·modules·(ppc64le)</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_module_load_ppc64le_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-enable_fips_mode_ocil:questionnaire:1">
89 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>89 ······<ocil:title>Enable·FIPS·Mode</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-enable_fips_mode_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_telnet-server_removed_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-audit_owner_change_failed_ppc64le_ocil:questionnaire:1">
95 ······<ocil:title>Uninstall·telnet-server·Package</ocil:title>95 ······<ocil:title>Configure·auditing·of·unsuccessful·ownership·changes·(ppc64le)</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_telnet-server_removed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_owner_change_failed_ppc64le_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_network_scripts_ocil:questionnaire:1"> 
101 ······<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-package_usbguard_installed_ocil:questionnaire:1">
 101 ······<ocil:title>Install·usbguard·Package</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_network_scripts_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-package_usbguard_installed_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_gcc_plugin_randstruct_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_syn_cookies_ocil:questionnaire:1">
107 ······<ocil:title>Randomize·layout·of·sensitive·kernel·structures</ocil:title>107 ······<ocil:title>Enable·TCP/IP·syncookie·support</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_gcc_plugin_randstruct_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_syn_cookies_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-tftp_uses_secure_mode_systemd_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·tftp·systemd·Service·Uses·Secure·Mode</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-network_nmcli_permissions_ocil:questionnaire:1">
 113 ······<ocil:title>Prevent·non-Privileged·Users·from·Modifying·Network·Interfaces·using·nmcli</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-tftp_uses_secure_mode_systemd_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-network_nmcli_permissions_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1"> 
119 ······<ocil:title>Unmap·kernel·when·running·in·userspace·(aka·KAISER)</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-file_permission_user_init_files_root_ocil:questionnaire:1">
 119 ······<ocil:title>Ensure·All·User·Initialization·Files·Have·Mode·0740·Or·Less·Permissive</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-kernel_config_unmap_kernel_at_el0_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-file_permission_user_init_files_root_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1"> 
Max diff block lines reached; 2143706/2156772 bytes (99.39%) of diff not shown.
2.5 KB
./usr/share/xml/scap/ssg/content/ssg-rhel10-xccdf.xml
2.4 KB
./usr/share/xml/scap/ssg/content/ssg-rhel10-xccdf.xml
Ordering differences only
    
Offset 279, 23 lines modifiedOffset 279, 23 lines modified
279 ······</cpe-lang:logical-test>279 ······</cpe-lang:logical-test>
280 ····</cpe-lang:platform>280 ····</cpe-lang:platform>
281 ····<cpe-lang:platform·id="package_bash">281 ····<cpe-lang:platform·id="package_bash">
282 ······<cpe-lang:logical-test·operator="AND"·negate="false">282 ······<cpe-lang:logical-test·operator="AND"·negate="false">
283 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>283 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
284 ······</cpe-lang:logical-test>284 ······</cpe-lang:logical-test>
285 ····</cpe-lang:platform>285 ····</cpe-lang:platform>
286 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">286 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
287 ······<cpe-lang:logical-test·operator="AND"·negate="false">287 ······<cpe-lang:logical-test·operator="AND"·negate="false">
288 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>288 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
289 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
290 ······</cpe-lang:logical-test>289 ······</cpe-lang:logical-test>
291 ····</cpe-lang:platform>290 ····</cpe-lang:platform>
292 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">291 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
293 ······<cpe-lang:logical-test·operator="AND"·negate="false">292 ······<cpe-lang:logical-test·operator="AND"·negate="false">
294 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>293 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 294 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
295 ······</cpe-lang:logical-test>295 ······</cpe-lang:logical-test>
296 ····</cpe-lang:platform>296 ····</cpe-lang:platform>
297 ····<cpe-lang:platform·id="not_s390x_arch">297 ····<cpe-lang:platform·id="not_s390x_arch">
298 ······<cpe-lang:logical-test·operator="AND"·negate="false">298 ······<cpe-lang:logical-test·operator="AND"·negate="false">
299 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>299 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
300 ······</cpe-lang:logical-test>300 ······</cpe-lang:logical-test>
301 ····</cpe-lang:platform>301 ····</cpe-lang:platform>
3.41 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
3.41 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>
Offset 71, 15 lines modifiedOffset 71, 15 lines modified
71 ······</cpe-dict:cpe-item>71 ······</cpe-dict:cpe-item>
72 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.9">72 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.9">
73 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.9</cpe-dict:title>73 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.9</cpe-dict:title>
74 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8_9:def:1</cpe-dict:check>74 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8_9:def:1</cpe-dict:check>
75 ······</cpe-dict:cpe-item>75 ······</cpe-dict:cpe-item>
76 ····</cpe-dict:cpe-list>76 ····</cpe-dict:cpe-list>
77 ··</ds:component>77 ··</ds:component>
78 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-02-28T20:08:00">78 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
79 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">79 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
80 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>80 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
81 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>81 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>
82 ······<xccdf-1.2:description>82 ······<xccdf-1.2:description>
83 ········This·guide·presents·a·catalog·of·security-relevant83 ········This·guide·presents·a·catalog·of·security-relevant
84 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of84 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of
85 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)85 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 317526, 15 lines modifiedOffset 317526, 15 lines modified
317526 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>317526 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
317527 ············</xccdf-1.2:check>317527 ············</xccdf-1.2:check>
317528 ··········</xccdf-1.2:Rule>317528 ··········</xccdf-1.2:Rule>
317529 ········</xccdf-1.2:Group>317529 ········</xccdf-1.2:Group>
317530 ······</xccdf-1.2:Group>317530 ······</xccdf-1.2:Group>
317531 ····</xccdf-1.2:Benchmark>317531 ····</xccdf-1.2:Benchmark>
317532 ··</ds:component>317532 ··</ds:component>
317533 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-02-28T20:08:00">317533 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-03-01T22:08:00">
317534 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">317534 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
317535 ······<oval-def:generator>317535 ······<oval-def:generator>
317536 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>317536 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
317537 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>317537 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
317538 ········<oval:schema_version>5.11</oval:schema_version>317538 ········<oval:schema_version>5.11</oval:schema_version>
317539 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>317539 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
317540 ······</oval-def:generator>317540 ······</oval-def:generator>
Offset 385018, 18135 lines modifiedOffset 385018, 18135 lines modified
385018 ············</oval-def:arithmetic>385018 ············</oval-def:arithmetic>
385019 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>385019 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>
385020 ··········</oval-def:arithmetic>385020 ··········</oval-def:arithmetic>
385021 ········</oval-def:local_variable>385021 ········</oval-def:local_variable>
385022 ······</oval-def:variables>385022 ······</oval-def:variables>
385023 ····</oval-def:oval_definitions>385023 ····</oval-def:oval_definitions>
385024 ··</ds:component>385024 ··</ds:component>
385025 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-02-28T20:08:00">385025 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-03-01T22:08:00">
385026 ····<ocil:ocil>385026 ····<ocil:ocil>
385027 ······<ocil:generator>385027 ······<ocil:generator>
385028 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>385028 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
385029 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>385029 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
385030 ········<ocil:schema_version>2.0</ocil:schema_version>385030 ········<ocil:schema_version>2.0</ocil:schema_version>
385031 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>385031 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
385032 ······</ocil:generator>385032 ······</ocil:generator>
385033 ······<ocil:questionnaires>385033 ······<ocil:questionnaires>
385034 ········<ocil:questionnaire·id="ocil:ssg-mount_option_boot_efi_nosuid_ocil:questionnaire:1">385034 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1">
385035 ··········<ocil:title>Add·nosuid·Option·to·/boot/efi</ocil:title>385035 ··········<ocil:title>Verify·User·Who·Owns·Backup·passwd·File</ocil:title>
385036 ··········<ocil:actions>385036 ··········<ocil:actions>
385037 ············<ocil:test_action_ref>ocil:ssg-mount_option_boot_efi_nosuid_action:testaction:1</ocil:test_action_ref>385037 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
385038 ··········</ocil:actions>385038 ··········</ocil:actions>
385039 ········</ocil:questionnaire>385039 ········</ocil:questionnaire>
385040 ········<ocil:questionnaire·id="ocil:ssg-directory_group_ownership_var_log_audit_ocil:questionnaire:1">385040 ········<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1">
385041 ··········<ocil:title>System·Audit·Directories·Must·Be·Group·Owned·By·Root</ocil:title>385041 ··········<ocil:title>Uninstall·rsh-server·Package</ocil:title>
385042 ··········<ocil:actions>385042 ··········<ocil:actions>
385043 ············<ocil:test_action_ref>ocil:ssg-directory_group_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>385043 ············<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref>
385044 ··········</ocil:actions>385044 ··········</ocil:actions>
385045 ········</ocil:questionnaire>385045 ········</ocil:questionnaire>
385046 ········<ocil:questionnaire·id="ocil:ssg-mount_option_home_nosuid_ocil:questionnaire:1">385046 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_ocil:questionnaire:1">
385047 ··········<ocil:title>Add·nosuid·Option·to·/home</ocil:title>385047 ··········<ocil:title>Emulate·Privileged·Access·Never·(PAN)</ocil:title>
385048 ··········<ocil:actions>385048 ··········<ocil:actions>
385049 ············<ocil:test_action_ref>ocil:ssg-mount_option_home_nosuid_action:testaction:1</ocil:test_action_ref>385049 ············<ocil:test_action_ref>ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_action:testaction:1</ocil:test_action_ref>
385050 ··········</ocil:actions>385050 ··········</ocil:actions>
385051 ········</ocil:questionnaire>385051 ········</ocil:questionnaire>
385052 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount_ocil:questionnaire:1">385052 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_login_uids_ocil:questionnaire:1">
385053 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount</ocil:title>385053 ··········<ocil:title>Configure·immutable·Audit·login·UIDs</ocil:title>
385054 ··········<ocil:actions>385054 ··········<ocil:actions>
385055 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount_action:testaction:1</ocil:test_action_ref>385055 ············<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_login_uids_action:testaction:1</ocil:test_action_ref>
385056 ··········</ocil:actions>385056 ··········</ocil:actions>
385057 ········</ocil:questionnaire>385057 ········</ocil:questionnaire>
385058 ········<ocil:questionnaire·id="ocil:ssg-file_etc_security_opasswd_ocil:questionnaire:1">385058 ········<ocil:questionnaire·id="ocil:ssg-selinux_all_devicefiles_labeled_ocil:questionnaire:1">
385059 ··········<ocil:title>Verify·Permissions·and·Ownership·of·Old·Passwords·File</ocil:title>385059 ··········<ocil:title>Ensure·No·Device·Files·are·Unlabeled·by·SELinux</ocil:title>
385060 ··········<ocil:actions>385060 ··········<ocil:actions>
385061 ············<ocil:test_action_ref>ocil:ssg-file_etc_security_opasswd_action:testaction:1</ocil:test_action_ref>385061 ············<ocil:test_action_ref>ocil:ssg-selinux_all_devicefiles_labeled_action:testaction:1</ocil:test_action_ref>
385062 ··········</ocil:actions>385062 ··········</ocil:actions>
385063 ········</ocil:questionnaire>385063 ········</ocil:questionnaire>
385064 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">385064 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1">
385065 ··········<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>385065 ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title>
385066 ··········<ocil:actions>385066 ··········<ocil:actions>
385067 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>385067 ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref>
385068 ··········</ocil:actions>385068 ··········</ocil:actions>
385069 ········</ocil:questionnaire>385069 ········</ocil:questionnaire>
385070 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1">385070 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1">
385071 ··········<ocil:title>Disable·SSH·Support·for·.rhosts·Files</ocil:title>385071 ··········<ocil:title>Configure·audit·according·to·OSPP·requirements</ocil:title>
385072 ··········<ocil:actions>385072 ··········<ocil:actions>
385073 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_action:testaction:1</ocil:test_action_ref>385073 ············<ocil:test_action_ref>ocil:ssg-audit_rules_for_ospp_action:testaction:1</ocil:test_action_ref>
385074 ··········</ocil:actions>385074 ··········</ocil:actions>
385075 ········</ocil:questionnaire>385075 ········</ocil:questionnaire>
385076 ········<ocil:questionnaire·id="ocil:ssg-httpd_enable_system_logging_ocil:questionnaire:1">385076 ········<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">
385077 ··········<ocil:title>Enable·HTTPD·System·Logging</ocil:title>385077 ··········<ocil:title>The·Chrony·package·is·installed</ocil:title>
385078 ··········<ocil:actions>385078 ··········<ocil:actions>
385079 ············<ocil:test_action_ref>ocil:ssg-httpd_enable_system_logging_action:testaction:1</ocil:test_action_ref>385079 ············<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>
385080 ··········</ocil:actions>385080 ··········</ocil:actions>
385081 ········</ocil:questionnaire>385081 ········</ocil:questionnaire>
385082 ········<ocil:questionnaire·id="ocil:ssg-no_legacy_plus_entries_etc_shadow_ocil:questionnaire:1">385082 ········<ocil:questionnaire·id="ocil:ssg-sebool_cobbler_can_network_connect_ocil:questionnaire:1">
385083 ··········<ocil:title>Ensure·there·are·no·legacy·+·NIS·entries·in·/etc/shadow</ocil:title>385083 ··········<ocil:title>Disable·the·cobbler_can_network_connect·SELinux·Boolean</ocil:title>
385084 ··········<ocil:actions>385084 ··········<ocil:actions>
385085 ············<ocil:test_action_ref>ocil:ssg-no_legacy_plus_entries_etc_shadow_action:testaction:1</ocil:test_action_ref>385085 ············<ocil:test_action_ref>ocil:ssg-sebool_cobbler_can_network_connect_action:testaction:1</ocil:test_action_ref>
385086 ··········</ocil:actions>385086 ··········</ocil:actions>
385087 ········</ocil:questionnaire>385087 ········</ocil:questionnaire>
385088 ········<ocil:questionnaire·id="ocil:ssg-service_tftp_disabled_ocil:questionnaire:1">385088 ········<ocil:questionnaire·id="ocil:ssg-package_scap-security-guide_installed_ocil:questionnaire:1">
385089 ··········<ocil:title>Disable·tftp·Service</ocil:title>385089 ··········<ocil:title>Install·scap-security-guide·Package</ocil:title>
385090 ··········<ocil:actions>385090 ··········<ocil:actions>
385091 ············<ocil:test_action_ref>ocil:ssg-service_tftp_disabled_action:testaction:1</ocil:test_action_ref>385091 ············<ocil:test_action_ref>ocil:ssg-package_scap-security-guide_installed_action:testaction:1</ocil:test_action_ref>
385092 ··········</ocil:actions>385092 ··········</ocil:actions>
385093 ········</ocil:questionnaire>385093 ········</ocil:questionnaire>
385094 ········<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_ipsecd_ocil:questionnaire:1">385094 ········<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">
385095 ··········<ocil:title>Verify·User·Who·Owns·/etc/ipsec.d·Directory</ocil:title>385095 ··········<ocil:title>Verify·Owner·on·crontab</ocil:title>
385096 ··········<ocil:actions>385096 ··········<ocil:actions>
Max diff block lines reached; 3568422/3580580 bytes (99.66%) of diff not shown.
3.27 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ocil.xml
3.27 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ocil.xml
Ordering differences only
    
Offset 3, 18126 lines modifiedOffset 3, 18126 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_efi_nosuid_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1">
11 ······<ocil:title>Add·nosuid·Option·to·/boot/efi</ocil:title>11 ······<ocil:title>Verify·User·Who·Owns·Backup·passwd·File</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_efi_nosuid_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-directory_group_ownership_var_log_audit_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1">
17 ······<ocil:title>System·Audit·Directories·Must·Be·Group·Owned·By·Root</ocil:title>17 ······<ocil:title>Uninstall·rsh-server·Package</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-directory_group_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nosuid_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_ocil:questionnaire:1">
23 ······<ocil:title>Add·nosuid·Option·to·/home</ocil:title>23 ······<ocil:title>Emulate·Privileged·Access·Never·(PAN)</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nosuid_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_login_uids_ocil:questionnaire:1">
29 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount</ocil:title>29 ······<ocil:title>Configure·immutable·Audit·login·UIDs</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_login_uids_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_etc_security_opasswd_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-selinux_all_devicefiles_labeled_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Permissions·and·Ownership·of·Old·Passwords·File</ocil:title>35 ······<ocil:title>Ensure·No·Device·Files·are·Unlabeled·by·SELinux</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_etc_security_opasswd_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-selinux_all_devicefiles_labeled_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>41 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1">
47 ······<ocil:title>Disable·SSH·Support·for·.rhosts·Files</ocil:title>47 ······<ocil:title>Configure·audit·according·to·OSPP·requirements</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_for_ospp_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-httpd_enable_system_logging_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">
53 ······<ocil:title>Enable·HTTPD·System·Logging</ocil:title>53 ······<ocil:title>The·Chrony·package·is·installed</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-httpd_enable_system_logging_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-no_legacy_plus_entries_etc_shadow_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sebool_cobbler_can_network_connect_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·there·are·no·legacy·+·NIS·entries·in·/etc/shadow</ocil:title>59 ······<ocil:title>Disable·the·cobbler_can_network_connect·SELinux·Boolean</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-no_legacy_plus_entries_etc_shadow_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sebool_cobbler_can_network_connect_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-service_tftp_disabled_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-package_scap-security-guide_installed_ocil:questionnaire:1">
65 ······<ocil:title>Disable·tftp·Service</ocil:title>65 ······<ocil:title>Install·scap-security-guide·Package</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-service_tftp_disabled_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-package_scap-security-guide_installed_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_ipsecd_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">
71 ······<ocil:title>Verify·User·Who·Owns·/etc/ipsec.d·Directory</ocil:title>71 ······<ocil:title>Verify·Owner·on·crontab</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-directory_owner_etc_ipsecd_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_ocil:questionnaire:1"> 
77 ······<ocil:title>Configure·Accepting·Router·Preference·in·Router·Advertisements·on·All·IPv6·Interfaces</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1">
 77 ······<ocil:title>Set·Lockout·Time·for·Failed·Password·Attempts</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_unlock_time_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_chrony_keys_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_grub2_cfg_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Group·Who·Owns·/etc/chrony.keys·File</ocil:title>83 ······<ocil:title>Verify·/boot/grub2/grub.cfg·Permissions</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_chrony_keys_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_grub2_cfg_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-package_gssproxy_removed_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_private_key_ocil:questionnaire:1">
89 ······<ocil:title>Uninstall·gssproxy·Package</ocil:title>89 ······<ocil:title>Verify·Group·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-package_gssproxy_removed_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-selinux_user_login_roles_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-dir_perms_world_writable_system_owned_ocil:questionnaire:1">
95 ······<ocil:title>Map·System·Users·To·The·Appropriate·SELinux·Role</ocil:title>95 ······<ocil:title>Ensure·All·World-Writable·Directories·Are·Owned·by·a·System·Account</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-selinux_user_login_roles_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_system_owned_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_user_cfg_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-file_owner_efi_grub2_cfg_ocil:questionnaire:1">
101 ······<ocil:title>Verify·/boot/grub2/user.cfg·Permissions</ocil:title>101 ······<ocil:title>Verify·the·UEFI·Boot·Loader·grub.cfg·User·Ownership</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_permissions_user_cfg_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_owner_efi_grub2_cfg_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_httpd_server_conf_d_files_ocil:questionnaire:1">
107 ······<ocil:title>Verify·that·audit·tools·Have·Mode·0755·or·less</ocil:title>107 ······<ocil:title>Set·Permissions·on·All·Configuration·Files·Inside·/etc/httpd/conf.d/</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_audit_binaries_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_httpd_server_conf_d_files_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-directory_groupowner_etc_selinux_ocil:questionnaire:1"> 
113 ······<ocil:title>Verify·Group·Who·Owns·/etc/selinux·Directory</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-package_avahi-autoipd_removed_ocil:questionnaire:1">
 113 ······<ocil:title>Uninstall·avahi-autoipd·Server·Package</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-directory_groupowner_etc_selinux_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-package_avahi-autoipd_removed_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sebool_smartmon_3ware_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-securetty_root_login_console_only_ocil:questionnaire:1">
119 ······<ocil:title>Disable·the·smartmon_3ware·SELinux·Boolean</ocil:title>119 ······<ocil:title>Restrict·Virtual·Console·Root·Logins</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sebool_smartmon_3ware_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-securetty_root_login_console_only_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-postfix_network_listening_disabled_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-file_audit_tools_permissions_ocil:questionnaire:1">
125 ······<ocil:title>Disable·Postfix·Network·Listening</ocil:title>125 ······<ocil:title>Audit·Tools·Must·Have·a·Mode·of·0755·or·Less·Permissive</ocil:title>
126 ······<ocil:actions>126 ······<ocil:actions>
127 ········<ocil:test_action_ref>ocil:ssg-postfix_network_listening_disabled_action:testaction:1</ocil:test_action_ref>127 ········<ocil:test_action_ref>ocil:ssg-file_audit_tools_permissions_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 3419454/3432546 bytes (99.62%) of diff not shown.
3.29 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
3.29 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of40 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 310419, 15 lines modifiedOffset 310419, 15 lines modified
310419 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>310419 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
310420 ············</xccdf-1.2:check>310420 ············</xccdf-1.2:check>
310421 ··········</xccdf-1.2:Rule>310421 ··········</xccdf-1.2:Rule>
310422 ········</xccdf-1.2:Group>310422 ········</xccdf-1.2:Group>
310423 ······</xccdf-1.2:Group>310423 ······</xccdf-1.2:Group>
310424 ····</xccdf-1.2:Benchmark>310424 ····</xccdf-1.2:Benchmark>
310425 ··</ds:component>310425 ··</ds:component>
310426 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-02-28T20:08:00">310426 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-03-01T22:08:00">
310427 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">310427 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
310428 ······<oval-def:generator>310428 ······<oval-def:generator>
310429 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>310429 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
310430 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>310430 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
310431 ········<oval:schema_version>5.11</oval:schema_version>310431 ········<oval:schema_version>5.11</oval:schema_version>
310432 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>310432 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
310433 ······</oval-def:generator>310433 ······</oval-def:generator>
Offset 377198, 20441 lines modifiedOffset 377198, 20442 lines modified
377198 ············</oval-def:arithmetic>377198 ············</oval-def:arithmetic>
377199 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>377199 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
377200 ··········</oval-def:arithmetic>377200 ··········</oval-def:arithmetic>
377201 ········</oval-def:local_variable>377201 ········</oval-def:local_variable>
377202 ······</oval-def:variables>377202 ······</oval-def:variables>
377203 ····</oval-def:oval_definitions>377203 ····</oval-def:oval_definitions>
377204 ··</ds:component>377204 ··</ds:component>
377205 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-02-28T20:08:00">377205 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-03-01T22:08:00">
377206 ····<ocil:ocil>377206 ····<ocil:ocil>
377207 ······<ocil:generator>377207 ······<ocil:generator>
377208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>377208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
377209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>377209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
377210 ········<ocil:schema_version>2.0</ocil:schema_version>377210 ········<ocil:schema_version>2.0</ocil:schema_version>
377211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>377211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
377212 ······</ocil:generator>377212 ······</ocil:generator>
377213 ······<ocil:questionnaires>377213 ······<ocil:questionnaires>
377214 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_drop_in_config_ocil:questionnaire:1">377214 ········<ocil:questionnaire·id="ocil:ssg-file_audit_tools_group_ownership_ocil:questionnaire:1">
377215 ··········<ocil:title>Verify·Permissions·on·SSH·Server·Config·File</ocil:title>377215 ··········<ocil:title>Audit·Tools·Must·Be·Group-owned·by·Root</ocil:title>
377216 ··········<ocil:actions>377216 ··········<ocil:actions>
377217 ············<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_drop_in_config_action:testaction:1</ocil:test_action_ref>377217 ············<ocil:test_action_ref>ocil:ssg-file_audit_tools_group_ownership_action:testaction:1</ocil:test_action_ref>
377218 ··········</ocil:actions>377218 ··········</ocil:actions>
377219 ········</ocil:questionnaire>377219 ········</ocil:questionnaire>
377220 ········<ocil:questionnaire·id="ocil:ssg-sebool_git_cgi_enable_homedirs_ocil:questionnaire:1">377220 ········<ocil:questionnaire·id="ocil:ssg-sebool_httpd_ssi_exec_ocil:questionnaire:1">
377221 ··········<ocil:title>Disable·the·git_cgi_enable_homedirs·SELinux·Boolean</ocil:title>377221 ··········<ocil:title>Disable·the·httpd_ssi_exec·SELinux·Boolean</ocil:title>
377222 ··········<ocil:actions>377222 ··········<ocil:actions>
377223 ············<ocil:test_action_ref>ocil:ssg-sebool_git_cgi_enable_homedirs_action:testaction:1</ocil:test_action_ref>377223 ············<ocil:test_action_ref>ocil:ssg-sebool_httpd_ssi_exec_action:testaction:1</ocil:test_action_ref>
377224 ··········</ocil:actions>377224 ··········</ocil:actions>
377225 ········</ocil:questionnaire>377225 ········</ocil:questionnaire>
377226 ········<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">377226 ········<ocil:questionnaire·id="ocil:ssg-sebool_exim_read_user_files_ocil:questionnaire:1">
377227 ··········<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>377227 ··········<ocil:title>Disable·the·exim_read_user_files·SELinux·Boolean</ocil:title>
377228 ··········<ocil:actions>377228 ··········<ocil:actions>
377229 ············<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>377229 ············<ocil:test_action_ref>ocil:ssg-sebool_exim_read_user_files_action:testaction:1</ocil:test_action_ref>
377230 ··········</ocil:actions>377230 ··········</ocil:actions>
377231 ········</ocil:questionnaire>377231 ········</ocil:questionnaire>
377232 ········<ocil:questionnaire·id="ocil:ssg-audit_access_success_aarch64_ocil:questionnaire:1">377232 ········<ocil:questionnaire·id="ocil:ssg-file_cron_allow_exists_ocil:questionnaire:1">
377233 ··········<ocil:title>Configure·auditing·of·successful·file·accesses·(AArch64)</ocil:title>377233 ··········<ocil:title>Ensure·that·/etc/cron.allow·exists</ocil:title>
377234 ··········<ocil:actions>377234 ··········<ocil:actions>
377235 ············<ocil:test_action_ref>ocil:ssg-audit_access_success_aarch64_action:testaction:1</ocil:test_action_ref>377235 ············<ocil:test_action_ref>ocil:ssg-file_cron_allow_exists_action:testaction:1</ocil:test_action_ref>
377236 ··········</ocil:actions>377236 ··········</ocil:actions>
377237 ········</ocil:questionnaire>377237 ········</ocil:questionnaire>
377238 ········<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">377238 ········<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1">
377239 ··········<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>377239 ··········<ocil:title>Enable·cron·Service</ocil:title>
377240 ··········<ocil:actions>377240 ··········<ocil:actions>
377241 ············<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>377241 ············<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref>
377242 ··········</ocil:actions>377242 ··········</ocil:actions>
377243 ········</ocil:questionnaire>377243 ········</ocil:questionnaire>
377244 ········<ocil:questionnaire·id="ocil:ssg-sebool_httpd_run_stickshift_ocil:questionnaire:1">377244 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1">
377245 ··········<ocil:title>Disable·the·httpd_run_stickshift·SELinux·Boolean</ocil:title>377245 ··········<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title>
377246 ··········<ocil:actions>377246 ··········<ocil:actions>
377247 ············<ocil:test_action_ref>ocil:ssg-sebool_httpd_run_stickshift_action:testaction:1</ocil:test_action_ref>377247 ············<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref>
377248 ··········</ocil:actions>377248 ··········</ocil:actions>
377249 ········</ocil:questionnaire>377249 ········</ocil:questionnaire>
377250 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_syn_cookies_ocil:questionnaire:1"> 
377251 ··········<ocil:title>Enable·TCP/IP·syncookie·support</ocil:title>377250 ········<ocil:questionnaire·id="ocil:ssg-audit_modify_failed_ppc64le_ocil:questionnaire:1">
 377251 ··········<ocil:title>Configure·auditing·of·unsuccessful·file·modifications·(ppc64le)</ocil:title>
377252 ··········<ocil:actions>377252 ··········<ocil:actions>
377253 ············<ocil:test_action_ref>ocil:ssg-kernel_config_syn_cookies_action:testaction:1</ocil:test_action_ref>377253 ············<ocil:test_action_ref>ocil:ssg-audit_modify_failed_ppc64le_action:testaction:1</ocil:test_action_ref>
377254 ··········</ocil:actions>377254 ··········</ocil:actions>
377255 ········</ocil:questionnaire>377255 ········</ocil:questionnaire>
377256 ········<ocil:questionnaire·id="ocil:ssg-sssd_certificate_verification_ocil:questionnaire:1">377256 ········<ocil:questionnaire·id="ocil:ssg-sebool_httpd_can_network_relay_ocil:questionnaire:1">
377257 ··········<ocil:title>Certificate·status·checking·in·SSSD</ocil:title>377257 ··········<ocil:title>Disable·the·httpd_can_network_relay·SELinux·Boolean</ocil:title>
377258 ··········<ocil:actions>377258 ··········<ocil:actions>
377259 ············<ocil:test_action_ref>ocil:ssg-sssd_certificate_verification_action:testaction:1</ocil:test_action_ref>377259 ············<ocil:test_action_ref>ocil:ssg-sebool_httpd_can_network_relay_action:testaction:1</ocil:test_action_ref>
377260 ··········</ocil:actions>377260 ··········</ocil:actions>
377261 ········</ocil:questionnaire>377261 ········</ocil:questionnaire>
377262 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">377262 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_issue_net_ocil:questionnaire:1">
377263 ··········<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>377263 ··········<ocil:title>Verify·Group·Ownership·of·System·Login·Banner·for·Remote·Connections</ocil:title>
377264 ··········<ocil:actions>377264 ··········<ocil:actions>
377265 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>377265 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_net_action:testaction:1</ocil:test_action_ref>
377266 ··········</ocil:actions>377266 ··········</ocil:actions>
377267 ········</ocil:questionnaire>377267 ········</ocil:questionnaire>
377268 ········<ocil:questionnaire·id="ocil:ssg-sebool_mount_anyfile_ocil:questionnaire:1">377268 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_binaries_ocil:questionnaire:1">
377269 ··········<ocil:title>Enable·the·mount_anyfile·SELinux·Boolean</ocil:title>377269 ··········<ocil:title>Verify·that·audit·tools·are·owned·by·root</ocil:title>
377270 ··········<ocil:actions>377270 ··········<ocil:actions>
377271 ············<ocil:test_action_ref>ocil:ssg-sebool_mount_anyfile_action:testaction:1</ocil:test_action_ref>377271 ············<ocil:test_action_ref>ocil:ssg-file_ownership_audit_binaries_action:testaction:1</ocil:test_action_ref>
377272 ··········</ocil:actions>377272 ··········</ocil:actions>
377273 ········</ocil:questionnaire>377273 ········</ocil:questionnaire>
377274 ········<ocil:questionnaire·id="ocil:ssg-file_groupownership_audit_binaries_ocil:questionnaire:1">377274 ········<ocil:questionnaire·id="ocil:ssg-package_geolite2-city_removed_ocil:questionnaire:1">
377275 ··········<ocil:title>Verify·that·audit·tools·are·owned·by·group·root</ocil:title>377275 ··········<ocil:title>Uninstall·geolite2-city·Package</ocil:title>
377276 ··········<ocil:actions>377276 ··········<ocil:actions>
377277 ············<ocil:test_action_ref>ocil:ssg-file_groupownership_audit_binaries_action:testaction:1</ocil:test_action_ref>377277 ············<ocil:test_action_ref>ocil:ssg-package_geolite2-city_removed_action:testaction:1</ocil:test_action_ref>
377278 ··········</ocil:actions>377278 ··········</ocil:actions>
377279 ········</ocil:questionnaire>377279 ········</ocil:questionnaire>
377280 ········<ocil:questionnaire·id="ocil:ssg-sebool_cdrecord_read_content_ocil:questionnaire:1">377280 ········<ocil:questionnaire·id="ocil:ssg-dnf-automatic_security_updates_only_ocil:questionnaire:1">
377281 ··········<ocil:title>Disable·the·cdrecord_read_content·SELinux·Boolean</ocil:title>377281 ··········<ocil:title>Configure·dnf-automatic·to·Install·Only·Security·Updates</ocil:title>
377282 ··········<ocil:actions>377282 ··········<ocil:actions>
377283 ············<ocil:test_action_ref>ocil:ssg-sebool_cdrecord_read_content_action:testaction:1</ocil:test_action_ref>377283 ············<ocil:test_action_ref>ocil:ssg-dnf-automatic_security_updates_only_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 3437985/3450269 bytes (99.64%) of diff not shown.
3.16 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ocil.xml
3.16 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ocil.xml
Ordering differences only
    
Offset 3, 20432 lines modifiedOffset 3, 20433 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_drop_in_config_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_audit_tools_group_ownership_ocil:questionnaire:1">
11 ······<ocil:title>Verify·Permissions·on·SSH·Server·Config·File</ocil:title>11 ······<ocil:title>Audit·Tools·Must·Be·Group-owned·by·Root</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_drop_in_config_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_audit_tools_group_ownership_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-sebool_git_cgi_enable_homedirs_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-sebool_httpd_ssi_exec_ocil:questionnaire:1">
17 ······<ocil:title>Disable·the·git_cgi_enable_homedirs·SELinux·Boolean</ocil:title>17 ······<ocil:title>Disable·the·httpd_ssi_exec·SELinux·Boolean</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sebool_git_cgi_enable_homedirs_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sebool_httpd_ssi_exec_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-sebool_exim_read_user_files_ocil:questionnaire:1">
23 ······<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>23 ······<ocil:title>Disable·the·exim_read_user_files·SELinux·Boolean</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sebool_exim_read_user_files_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_access_success_aarch64_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_cron_allow_exists_ocil:questionnaire:1">
29 ······<ocil:title>Configure·auditing·of·successful·file·accesses·(AArch64)</ocil:title>29 ······<ocil:title>Ensure·that·/etc/cron.allow·exists</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_access_success_aarch64_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_cron_allow_exists_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>35 ······<ocil:title>Enable·cron·Service</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sebool_httpd_run_stickshift_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1">
41 ······<ocil:title>Disable·the·httpd_run_stickshift·SELinux·Boolean</ocil:title>41 ······<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sebool_httpd_run_stickshift_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_syn_cookies_ocil:questionnaire:1"> 
47 ······<ocil:title>Enable·TCP/IP·syncookie·support</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-audit_modify_failed_ppc64le_ocil:questionnaire:1">
 47 ······<ocil:title>Configure·auditing·of·unsuccessful·file·modifications·(ppc64le)</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-kernel_config_syn_cookies_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_modify_failed_ppc64le_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sssd_certificate_verification_ocil:questionnaire:1"> 
53 ······<ocil:title>Certificate·status·checking·in·SSSD</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-sebool_httpd_can_network_relay_ocil:questionnaire:1">
 53 ······<ocil:title>Disable·the·httpd_can_network_relay·SELinux·Boolean</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sssd_certificate_verification_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sebool_httpd_can_network_relay_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_issue_net_ocil:questionnaire:1">
59 ······<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>59 ······<ocil:title>Verify·Group·Ownership·of·System·Login·Banner·for·Remote·Connections</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_net_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sebool_mount_anyfile_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_binaries_ocil:questionnaire:1">
65 ······<ocil:title>Enable·the·mount_anyfile·SELinux·Boolean</ocil:title>65 ······<ocil:title>Verify·that·audit·tools·are·owned·by·root</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sebool_mount_anyfile_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_ownership_audit_binaries_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_audit_binaries_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-package_geolite2-city_removed_ocil:questionnaire:1">
71 ······<ocil:title>Verify·that·audit·tools·are·owned·by·group·root</ocil:title>71 ······<ocil:title>Uninstall·geolite2-city·Package</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_audit_binaries_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-package_geolite2-city_removed_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sebool_cdrecord_read_content_ocil:questionnaire:1"> 
77 ······<ocil:title>Disable·the·cdrecord_read_content·SELinux·Boolean</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-dnf-automatic_security_updates_only_ocil:questionnaire:1">
 77 ······<ocil:title>Configure·dnf-automatic·to·Install·Only·Security·Updates</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sebool_cdrecord_read_content_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-dnf-automatic_security_updates_only_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sebool_gssd_read_tmp_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1">
83 ······<ocil:title>Enable·the·gssd_read_tmp·SELinux·Boolean</ocil:title>83 ······<ocil:title>Disable·SSH·Support·for·.rhosts·Files</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sebool_gssd_read_tmp_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-bios_enable_execution_restrictions_ocil:questionnaire:1"> 
89 ······<ocil:title>Enable·NX·or·XD·Support·in·the·BIOS</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1">
 89 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-bios_enable_execution_restrictions_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_opasswd_ocil:questionnaire:1"> 
95 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/security/opasswd</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_minlen_login_defs_ocil:questionnaire:1">
 95 ······<ocil:title>Set·Password·Minimum·Length·in·login.defs</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_opasswd_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-accounts_password_minlen_login_defs_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-package_cryptsetup-luks_installed_ocil:questionnaire:1">
101 ······<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title>101 ······<ocil:title>Install·cryptsetup·Package</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-package_cryptsetup-luks_installed_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sebool_zoneminder_anon_write_ocil:questionnaire:1"> 
107 ······<ocil:title>Disable·the·zoneminder_anon_write·SELinux·Boolean</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_interactive_users_ocil:questionnaire:1">
 107 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·For·Interactive·Users</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sebool_zoneminder_anon_write_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_interactive_users_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sebool_httpd_ssi_exec_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_chrony_keys_ocil:questionnaire:1">
113 ······<ocil:title>Disable·the·httpd_ssi_exec·SELinux·Boolean</ocil:title>113 ······<ocil:title>Verify·User·Who·Owns·/etc/chrony.keys·File</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sebool_httpd_ssi_exec_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_chrony_keys_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sebool_ftpd_anon_write_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_cis_ocil:questionnaire:1">
119 ······<ocil:title>Disable·the·ftpd_anon_write·SELinux·Boolean</ocil:title>119 ······<ocil:title>Ensure·Local·Login·Warning·Banner·Is·Configured·Properly</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sebool_ftpd_anon_write_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_cis_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
Max diff block lines reached; 3297984/3310654 bytes (99.62%) of diff not shown.
1.57 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds.xml
1.57 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds.xml
    
Offset 19, 27 lines modifiedOffset 19, 27 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:enterprise_virtualization_manager:4">28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:enterprise_virtualization_manager:4">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Manager</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Manager</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_app_is_rhv4:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_app_is_rhv4:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8::hypervisor">32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8::hypervisor">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Host</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Host</cpe-dict:title>
34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_OS_is_rhv4:def:1</cpe-dict:check>34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_OS_is_rhv4:def:1</cpe-dict:check>
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ····</cpe-dict:cpe-list>36 ····</cpe-dict:cpe-list>
37 ··</ds:component>37 ··</ds:component>
38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-xccdf.xml"·timestamp="2025-02-28T20:08:00">38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-xccdf.xml"·timestamp="2025-03-01T22:08:00">
39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHV-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHV-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Virtualization·4</xccdf-1.2:title>41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Virtualization·4</xccdf-1.2:title>
42 ······<xccdf-1.2:description>42 ······<xccdf-1.2:description>
43 ········This·guide·presents·a·catalog·of·security-relevant43 ········This·guide·presents·a·catalog·of·security-relevant
44 configuration·settings·for·Red·Hat·Virtualization·4.·It·is·a·rendering·of44 configuration·settings·for·Red·Hat·Virtualization·4.·It·is·a·rendering·of
45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 162832, 15 lines modifiedOffset 162832, 15 lines modified
162832 ··············<xccdf-1.2:check-content-ref·href="ssg-rhv4-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>162832 ··············<xccdf-1.2:check-content-ref·href="ssg-rhv4-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
162833 ············</xccdf-1.2:check>162833 ············</xccdf-1.2:check>
162834 ··········</xccdf-1.2:Rule>162834 ··········</xccdf-1.2:Rule>
162835 ········</xccdf-1.2:Group>162835 ········</xccdf-1.2:Group>
162836 ······</xccdf-1.2:Group>162836 ······</xccdf-1.2:Group>
162837 ····</xccdf-1.2:Benchmark>162837 ····</xccdf-1.2:Benchmark>
162838 ··</ds:component>162838 ··</ds:component>
162839 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-oval.xml"·timestamp="2025-02-28T20:08:00">162839 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-oval.xml"·timestamp="2025-03-01T22:08:00">
162840 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">162840 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
162841 ······<oval-def:generator>162841 ······<oval-def:generator>
162842 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>162842 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
162843 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>162843 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
162844 ········<oval:schema_version>5.11</oval:schema_version>162844 ········<oval:schema_version>5.11</oval:schema_version>
162845 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>162845 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
162846 ······</oval-def:generator>162846 ······</oval-def:generator>
Offset 195359, 6372 lines modifiedOffset 195359, 6372 lines modified
195359 ············</oval-def:arithmetic>195359 ············</oval-def:arithmetic>
195360 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>195360 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
195361 ··········</oval-def:arithmetic>195361 ··········</oval-def:arithmetic>
195362 ········</oval-def:local_variable>195362 ········</oval-def:local_variable>
195363 ······</oval-def:variables>195363 ······</oval-def:variables>
195364 ····</oval-def:oval_definitions>195364 ····</oval-def:oval_definitions>
195365 ··</ds:component>195365 ··</ds:component>
195366 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-ocil.xml"·timestamp="2025-02-28T20:08:00">195366 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-ocil.xml"·timestamp="2025-03-01T22:08:00">
195367 ····<ocil:ocil>195367 ····<ocil:ocil>
195368 ······<ocil:generator>195368 ······<ocil:generator>
195369 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>195369 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
195370 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>195370 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
195371 ········<ocil:schema_version>2.0</ocil:schema_version>195371 ········<ocil:schema_version>2.0</ocil:schema_version>
195372 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>195372 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
195373 ······</ocil:generator>195373 ······</ocil:generator>
195374 ······<ocil:questionnaires>195374 ······<ocil:questionnaires>
195375 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount2_ocil:questionnaire:1">195375 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1">
 195376 ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title>
195376 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount2</ocil:title> 
195377 ··········<ocil:actions> 
195378 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount2_action:testaction:1</ocil:test_action_ref> 
195379 ··········</ocil:actions> 
195380 ········</ocil:questionnaire> 
195381 ········<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1"> 
195382 ··········<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title> 
195383 ··········<ocil:actions> 
195384 ············<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref> 
195385 ··········</ocil:actions> 
195386 ········</ocil:questionnaire> 
195387 ········<ocil:questionnaire·id="ocil:ssg-directory_access_var_log_audit_ocil:questionnaire:1"> 
195388 ··········<ocil:title>Record·Access·Events·to·Audit·Log·Directory</ocil:title> 
195389 ··········<ocil:actions>195377 ··········<ocil:actions>
195390 ············<ocil:test_action_ref>ocil:ssg-directory_access_var_log_audit_action:testaction:1</ocil:test_action_ref>195378 ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref>
195391 ··········</ocil:actions>195379 ··········</ocil:actions>
195392 ········</ocil:questionnaire>195380 ········</ocil:questionnaire>
195393 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_creat_ocil:questionnaire:1">195381 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">
195394 ··········<ocil:title>Record·Successful·Access·Attempts·to·Files·-·creat</ocil:title>195382 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>
195395 ··········<ocil:actions>195383 ··········<ocil:actions>
195396 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_creat_action:testaction:1</ocil:test_action_ref>195384 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>
195397 ··········</ocil:actions>195385 ··········</ocil:actions>
195398 ········</ocil:questionnaire>195386 ········</ocil:questionnaire>
195399 ········<ocil:questionnaire·id="ocil:ssg-mount_option_home_usrquota_ocil:questionnaire:1"> 
195400 ··········<ocil:title>Add·usrquota·Option·to·/home</ocil:title>195387 ········<ocil:questionnaire·id="ocil:ssg-auditd_audispd_encrypt_sent_records_ocil:questionnaire:1">
 195388 ··········<ocil:title>Encrypt·Audit·Records·Sent·With·audispd·Plugin</ocil:title>
195401 ··········<ocil:actions>195389 ··········<ocil:actions>
195402 ············<ocil:test_action_ref>ocil:ssg-mount_option_home_usrquota_action:testaction:1</ocil:test_action_ref>195390 ············<ocil:test_action_ref>ocil:ssg-auditd_audispd_encrypt_sent_records_action:testaction:1</ocil:test_action_ref>
195403 ··········</ocil:actions>195391 ··········</ocil:actions>
195404 ········</ocil:questionnaire>195392 ········</ocil:questionnaire>
195405 ········<ocil:questionnaire·id="ocil:ssg-package_openssh-server_removed_ocil:questionnaire:1">195393 ········<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1">
195406 ··········<ocil:title>Remove·the·OpenSSH·Server·Package</ocil:title>195394 ··········<ocil:title>Disable·the·Automounter</ocil:title>
195407 ··········<ocil:actions>195395 ··········<ocil:actions>
195408 ············<ocil:test_action_ref>ocil:ssg-package_openssh-server_removed_action:testaction:1</ocil:test_action_ref>195396 ············<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref>
195409 ··········</ocil:actions>195397 ··········</ocil:actions>
195410 ········</ocil:questionnaire>195398 ········</ocil:questionnaire>
195411 ········<ocil:questionnaire·id="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1">195399 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
195412 ··········<ocil:title>Enforce·Spectre·v2·mitigation</ocil:title>195400 ··········<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
195413 ··········<ocil:actions>195401 ··········<ocil:actions>
195414 ············<ocil:test_action_ref>ocil:ssg-grub2_spectre_v2_argument_action:testaction:1</ocil:test_action_ref>195402 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
195415 ··········</ocil:actions>195403 ··········</ocil:actions>
195416 ········</ocil:questionnaire>195404 ········</ocil:questionnaire>
195417 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_shadow_ocil:questionnaire:1">195405 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">
195418 ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/shadow</ocil:title>195406 ··········<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
195419 ··········<ocil:actions>195407 ··········<ocil:actions>
195420 ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_shadow_action:testaction:1</ocil:test_action_ref>195408 ············<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
195421 ··········</ocil:actions>195409 ··········</ocil:actions>
195422 ········</ocil:questionnaire>195410 ········</ocil:questionnaire>
195423 ········<ocil:questionnaire·id="ocil:ssg-package_gdm_removed_ocil:questionnaire:1">195411 ········<ocil:questionnaire·id="ocil:ssg-file_owner_sshd_config_ocil:questionnaire:1">
195424 ··········<ocil:title>Remove·the·GDM·Package·Group</ocil:title>195412 ··········<ocil:title>Verify·Owner·on·SSH·Server·config·file</ocil:title>
195425 ··········<ocil:actions>195413 ··········<ocil:actions>
195426 ············<ocil:test_action_ref>ocil:ssg-package_gdm_removed_action:testaction:1</ocil:test_action_ref>195414 ············<ocil:test_action_ref>ocil:ssg-file_owner_sshd_config_action:testaction:1</ocil:test_action_ref>
195427 ··········</ocil:actions>195415 ··········</ocil:actions>
195428 ········</ocil:questionnaire>195416 ········</ocil:questionnaire>
195429 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_removexattr_ocil:questionnaire:1"> 
195430 ··········<ocil:title>Record·Successful·Permission·Changes·to·Files·-·removexattr</ocil:title>195417 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_ocil:questionnaire:1">
 195418 ··········<ocil:title>Enable·Kernel·Parameter·to·Log·Martian·Packets·on·all·IPv4·Interfaces</ocil:title>
195431 ··········<ocil:actions>195419 ··········<ocil:actions>
195432 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_removexattr_action:testaction:1</ocil:test_action_ref>195420 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_action:testaction:1</ocil:test_action_ref>
195433 ··········</ocil:actions>195421 ··········</ocil:actions>
195434 ········</ocil:questionnaire>195422 ········</ocil:questionnaire>
195435 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_ocil:questionnaire:1">195423 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1">
195436 ··········<ocil:title>Record·Events·that·Modify·User/Group·Information</ocil:title>195424 ··········<ocil:title>Verify·Group·Who·Owns·/var/log/messages·File</ocil:title>
195437 ··········<ocil:actions>195425 ··········<ocil:actions>
195438 ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_action:testaction:1</ocil:test_action_ref>195426 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_messages_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1631274/1642888 bytes (99.29%) of diff not shown.
1.5 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ocil.xml
1.5 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ocil.xml
Ordering differences only
    
Offset 3, 6363 lines modifiedOffset 3, 6363 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount2_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title>
11 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount2</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount2_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1"> 
17 ······<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-directory_access_var_log_audit_ocil:questionnaire:1"> 
23 ······<ocil:title>Record·Access·Events·to·Audit·Log·Directory</ocil:title> 
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-directory_access_var_log_audit_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_creat_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">
29 ······<ocil:title>Record·Successful·Access·Attempts·to·Files·-·creat</ocil:title>17 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_creat_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_usrquota_ocil:questionnaire:1"> 
35 ······<ocil:title>Add·usrquota·Option·to·/home</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_encrypt_sent_records_ocil:questionnaire:1">
 23 ······<ocil:title>Encrypt·Audit·Records·Sent·With·audispd·Plugin</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_usrquota_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_encrypt_sent_records_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_removed_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1">
41 ······<ocil:title>Remove·the·OpenSSH·Server·Package</ocil:title>29 ······<ocil:title>Disable·the·Automounter</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_removed_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
47 ······<ocil:title>Enforce·Spectre·v2·mitigation</ocil:title>35 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-grub2_spectre_v2_argument_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_shadow_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">
53 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/shadow</ocil:title>41 ······<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_shadow_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-package_gdm_removed_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_sshd_config_ocil:questionnaire:1">
59 ······<ocil:title>Remove·the·GDM·Package·Group</ocil:title>47 ······<ocil:title>Verify·Owner·on·SSH·Server·config·file</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-package_gdm_removed_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_owner_sshd_config_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_removexattr_ocil:questionnaire:1"> 
65 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·removexattr</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_ocil:questionnaire:1">
 53 ······<ocil:title>Enable·Kernel·Parameter·to·Log·Martian·Packets·on·all·IPv4·Interfaces</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_removexattr_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1">
71 ······<ocil:title>Record·Events·that·Modify·User/Group·Information</ocil:title>59 ······<ocil:title>Verify·Group·Who·Owns·/var/log/messages·File</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_messages_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"> 
77 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-grub2_mce_argument_ocil:questionnaire:1">
 65 ······<ocil:title>Force·kernel·panic·on·uncorrected·MCEs</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-grub2_mce_argument_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-service_zebra_disabled_ocil:questionnaire:1">
83 ······<ocil:title>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</ocil:title>71 ······<ocil:title>Disable·Quagga·Service</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-service_zebra_disabled_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1">
89 ······<ocil:title>Make·the·auditd·Configuration·Immutable</ocil:title>77 ······<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1"> 
95 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1">
 83 ······<ocil:title>Kernel·panic·oops</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_on_oops_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1"> 
101 ······<ocil:title>Enable·checks·on·scatter-gather·(SG)·table·operations</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-sebool_xdm_exec_bootloader_ocil:questionnaire:1">
 89 ······<ocil:title>Disable·the·xdm_exec_bootloader·SELinux·Boolean</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_sg_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sebool_xdm_exec_bootloader_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_reboot_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·reboot</ocil:title>95 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_reboot_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-service_zebra_disabled_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-service_sshd_enabled_ocil:questionnaire:1">
113 ······<ocil:title>Disable·Quagga·Service</ocil:title>101 ······<ocil:title>Enable·the·OpenSSH·Service</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-service_zebra_disabled_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-service_sshd_enabled_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-set_firewalld_default_zone_ocil:questionnaire:1"> 
119 ······<ocil:title>Set·Default·firewalld·Zone·for·Incoming·Packets</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1">
 107 ······<ocil:title>Verify·Permissions·on·gshadow·File</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-set_firewalld_default_zone_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_gshadow_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>110 ······</ocil:actions>
Max diff block lines reached; 1558457/1570499 bytes (99.23%) of diff not shown.
1.78 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds.xml
1.78 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds.xml
    
Offset 21, 27 lines modifiedOffset 21, 27 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.12-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.12-patch.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.12-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.12-patch.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:12">30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:12">
31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·12</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·12</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:12">34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:12">
35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·12</cpe-dict:title>35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·12</cpe-dict:title>
36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>
37 ······</cpe-dict:cpe-item>37 ······</cpe-dict:cpe-item>
38 ····</cpe-dict:cpe-list>38 ····</cpe-dict:cpe-list>
39 ··</ds:component>39 ··</ds:component>
40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-xccdf.xml"·timestamp="2025-02-28T20:08:00">40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-xccdf.xml"·timestamp="2025-03-01T22:08:00">
41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·12</xccdf-1.2:title>43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·12</xccdf-1.2:title>
44 ······<xccdf-1.2:description>44 ······<xccdf-1.2:description>
45 ········This·guide·presents·a·catalog·of·security-relevant45 ········This·guide·presents·a·catalog·of·security-relevant
46 configuration·settings·for·SUSE·Linux·Enterprise·12.·It·is·a·rendering·of46 configuration·settings·for·SUSE·Linux·Enterprise·12.·It·is·a·rendering·of
47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 186684, 15 lines modifiedOffset 186684, 15 lines modified
186684 ··············<xccdf-1.2:check-content-ref·href="ssg-sle12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>186684 ··············<xccdf-1.2:check-content-ref·href="ssg-sle12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
186685 ············</xccdf-1.2:check>186685 ············</xccdf-1.2:check>
186686 ··········</xccdf-1.2:Rule>186686 ··········</xccdf-1.2:Rule>
186687 ········</xccdf-1.2:Group>186687 ········</xccdf-1.2:Group>
186688 ······</xccdf-1.2:Group>186688 ······</xccdf-1.2:Group>
186689 ····</xccdf-1.2:Benchmark>186689 ····</xccdf-1.2:Benchmark>
186690 ··</ds:component>186690 ··</ds:component>
186691 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-oval.xml"·timestamp="2025-02-28T20:08:00">186691 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-oval.xml"·timestamp="2025-03-01T22:08:00">
186692 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">186692 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
186693 ······<oval-def:generator>186693 ······<oval-def:generator>
186694 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>186694 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
186695 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>186695 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
186696 ········<oval:schema_version>5.11</oval:schema_version>186696 ········<oval:schema_version>5.11</oval:schema_version>
186697 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>186697 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
186698 ······</oval-def:generator>186698 ······</oval-def:generator>
Offset 227001, 12188 lines modifiedOffset 227001, 12270 lines modified
227001 ············</oval-def:arithmetic>227001 ············</oval-def:arithmetic>
227002 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>227002 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
227003 ··········</oval-def:arithmetic>227003 ··········</oval-def:arithmetic>
227004 ········</oval-def:local_variable>227004 ········</oval-def:local_variable>
227005 ······</oval-def:variables>227005 ······</oval-def:variables>
227006 ····</oval-def:oval_definitions>227006 ····</oval-def:oval_definitions>
227007 ··</ds:component>227007 ··</ds:component>
227008 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-ocil.xml"·timestamp="2025-02-28T20:08:00">227008 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-ocil.xml"·timestamp="2025-03-01T22:08:00">
227009 ····<ocil:ocil>227009 ····<ocil:ocil>
227010 ······<ocil:generator>227010 ······<ocil:generator>
227011 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>227011 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
227012 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>227012 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
227013 ········<ocil:schema_version>2.0</ocil:schema_version>227013 ········<ocil:schema_version>2.0</ocil:schema_version>
227014 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>227014 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
227015 ······</ocil:generator>227015 ······</ocil:generator>
227016 ······<ocil:questionnaires>227016 ······<ocil:questionnaires>
227017 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_rmmod_ocil:questionnaire:1"> 
227018 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·rmmod</ocil:title> 
227019 ··········<ocil:actions> 
227020 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_rmmod_action:testaction:1</ocil:test_action_ref> 
227021 ··········</ocil:actions> 
227022 ········</ocil:questionnaire> 
227023 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_umount_ocil:questionnaire:1">227017 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1">
227024 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·umount</ocil:title>227018 ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title>
227025 ··········<ocil:actions> 
227026 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_umount_action:testaction:1</ocil:test_action_ref> 
227027 ··········</ocil:actions> 
227028 ········</ocil:questionnaire> 
227029 ········<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1"> 
227030 ··········<ocil:title>Disable·the·Automounter</ocil:title> 
227031 ··········<ocil:actions> 
227032 ············<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref> 
227033 ··········</ocil:actions> 
227034 ········</ocil:questionnaire> 
227035 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_ocil:questionnaire:1"> 
227036 ··········<ocil:title>Configure·Accepting·Default·Router·in·Router·Advertisements·on·All·IPv6·Interfaces·By·Default</ocil:title> 
227037 ··········<ocil:actions> 
227038 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_action:testaction:1</ocil:test_action_ref> 
227039 ··········</ocil:actions> 
227040 ········</ocil:questionnaire> 
227041 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1"> 
227042 ··········<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title> 
227043 ··········<ocil:actions> 
227044 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref> 
227045 ··········</ocil:actions> 
227046 ········</ocil:questionnaire> 
227047 ········<ocil:questionnaire·id="ocil:ssg-auditd_audispd_network_failure_action_ocil:questionnaire:1"> 
227048 ··········<ocil:title>Configure·audispd's·Plugin·network_failure_action·On·Network·Failure</ocil:title> 
227049 ··········<ocil:actions>227019 ··········<ocil:actions>
227050 ············<ocil:test_action_ref>ocil:ssg-auditd_audispd_network_failure_action_action:testaction:1</ocil:test_action_ref>227020 ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref>
227051 ··········</ocil:actions>227021 ··········</ocil:actions>
227052 ········</ocil:questionnaire>227022 ········</ocil:questionnaire>
227053 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1">227023 ········<ocil:questionnaire·id="ocil:ssg-susefirewall2_only_required_services_ocil:questionnaire:1">
227054 ··········<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>227024 ··········<ocil:title>Only·Allow·Authorized·Network·Services·in·SuSEfirewall2</ocil:title>
227055 ··········<ocil:actions>227025 ··········<ocil:actions>
227056 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>227026 ············<ocil:test_action_ref>ocil:ssg-susefirewall2_only_required_services_action:testaction:1</ocil:test_action_ref>
227057 ··········</ocil:actions>227027 ··········</ocil:actions>
227058 ········</ocil:questionnaire>227028 ········</ocil:questionnaire>
227059 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1"> 
227060 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmod</ocil:title>227029 ········<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1">
 227030 ··········<ocil:title>Do·Not·Allow·SSH·Environment·Options</ocil:title>
227061 ··········<ocil:actions>227031 ··········<ocil:actions>
227062 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmod_action:testaction:1</ocil:test_action_ref>227032 ············<ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref>
227063 ··········</ocil:actions>227033 ··········</ocil:actions>
227064 ········</ocil:questionnaire>227034 ········</ocil:questionnaire>
227065 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_newgrp_ocil:questionnaire:1"> 
227066 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·newgrp</ocil:title>227035 ········<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1">
 227036 ··········<ocil:title>Set·PAM''s·Password·Hashing·Algorithm</ocil:title>
227067 ··········<ocil:actions>227037 ··········<ocil:actions>
227068 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_newgrp_action:testaction:1</ocil:test_action_ref>227038 ············<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref>
227069 ··········</ocil:actions>227039 ··········</ocil:actions>
227070 ········</ocil:questionnaire>227040 ········</ocil:questionnaire>
227071 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_gshadow_ocil:questionnaire:1">227041 ········<ocil:questionnaire·id="ocil:ssg-no_forward_files_ocil:questionnaire:1">
227072 ··········<ocil:title>Verify·Group·Who·Owns·gshadow·File</ocil:title>227042 ··········<ocil:title>Verify·No·.forward·Files·Exist</ocil:title>
227073 ··········<ocil:actions>227043 ··········<ocil:actions>
227074 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_gshadow_action:testaction:1</ocil:test_action_ref>227044 ············<ocil:test_action_ref>ocil:ssg-no_forward_files_action:testaction:1</ocil:test_action_ref>
227075 ··········</ocil:actions>227045 ··········</ocil:actions>
227076 ········</ocil:questionnaire>227046 ········</ocil:questionnaire>
227077 ········<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">227047 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_chrony_keys_ocil:questionnaire:1">
227078 ··········<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>227048 ··········<ocil:title>Verify·User·Who·Owns·/etc/chrony.keys·File</ocil:title>
227079 ··········<ocil:actions>227049 ··········<ocil:actions>
227080 ············<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>227050 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_chrony_keys_action:testaction:1</ocil:test_action_ref>
227081 ··········</ocil:actions>227051 ··········</ocil:actions>
Max diff block lines reached; 1859197/1870340 bytes (99.40%) of diff not shown.
1.71 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ocil.xml
1.71 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ocil.xml
Ordering differences only
    
Offset 3, 12179 lines modifiedOffset 3, 12261 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_rmmod_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·rmmod</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_rmmod_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_umount_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1">
17 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·umount</ocil:title>11 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title>
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_umount_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1"> 
23 ······<ocil:title>Disable·the·Automounter</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_ocil:questionnaire:1"> 
29 ······<ocil:title>Configure·Accepting·Default·Router·in·Router·Advertisements·on·All·IPv6·Interfaces·By·Default</ocil:title> 
30 ······<ocil:actions> 
31 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_action:testaction:1</ocil:test_action_ref> 
32 ······</ocil:actions> 
33 ····</ocil:questionnaire> 
34 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1"> 
35 ······<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title> 
36 ······<ocil:actions> 
37 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref> 
38 ······</ocil:actions> 
39 ····</ocil:questionnaire> 
40 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_network_failure_action_ocil:questionnaire:1"> 
41 ······<ocil:title>Configure·audispd's·Plugin·network_failure_action·On·Network·Failure</ocil:title> 
42 ······<ocil:actions>12 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_network_failure_action_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>14 ······</ocil:actions>
45 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-susefirewall2_only_required_services_ocil:questionnaire:1">
47 ······<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>17 ······<ocil:title>Only·Allow·Authorized·Network·Services·in·SuSEfirewall2</ocil:title>
48 ······<ocil:actions>18 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-susefirewall2_only_required_services_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>20 ······</ocil:actions>
51 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1"> 
53 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmod</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1">
 23 ······<ocil:title>Do·Not·Allow·SSH·Environment·Options</ocil:title>
54 ······<ocil:actions>24 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmod_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>26 ······</ocil:actions>
57 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_newgrp_ocil:questionnaire:1"> 
59 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·newgrp</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1">
 29 ······<ocil:title>Set·PAM''s·Password·Hashing·Algorithm</ocil:title>
60 ······<ocil:actions>30 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_newgrp_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>32 ······</ocil:actions>
63 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_gshadow_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-no_forward_files_ocil:questionnaire:1">
65 ······<ocil:title>Verify·Group·Who·Owns·gshadow·File</ocil:title>35 ······<ocil:title>Verify·No·.forward·Files·Exist</ocil:title>
66 ······<ocil:actions>36 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_gshadow_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-no_forward_files_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>38 ······</ocil:actions>
69 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_chrony_keys_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>41 ······<ocil:title>Verify·User·Who·Owns·/etc/chrony.keys·File</ocil:title>
72 ······<ocil:actions>42 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_chrony_keys_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>44 ······</ocil:actions>
75 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1"> 
77 ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-journald_compress_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·journald·is·configured·to·compress·large·log·files</ocil:title>
78 ······<ocil:actions>48 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-journald_compress_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>50 ······</ocil:actions>
81 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_banner_enabled_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_interactive_home_directory_exists_ocil:questionnaire:1">
83 ······<ocil:title>Enable·GNOME3·Login·Warning·Banner</ocil:title>53 ······<ocil:title>All·Interactive·Users·Home·Directories·Must·Exist</ocil:title>
84 ······<ocil:actions>54 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_banner_enabled_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-accounts_user_interactive_home_directory_exists_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>56 ······</ocil:actions>
87 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1"> 
89 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_sshd_config_ocil:questionnaire:1">
 59 ······<ocil:title>Verify·Group·Who·Owns·SSH·Server·config·file</ocil:title>
90 ······<ocil:actions>60 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_sshd_config_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>62 ······</ocil:actions>
93 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sssd_enable_smartcards_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">
95 ······<ocil:title>Enable·Smartcards·in·SSSD</ocil:title>65 ······<ocil:title>Install·the·cron·service</ocil:title>
96 ······<ocil:actions>66 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sssd_enable_smartcards_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>68 ······</ocil:actions>
99 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-service_kdump_disabled_ocil:questionnaire:1">
101 ······<ocil:title>Disable·IPv6·Addressing·on·All·IPv6·Interfaces</ocil:title>71 ······<ocil:title>Disable·KDump·Kernel·Crash·Analyzer·(kdump)</ocil:title>
102 ······<ocil:actions>72 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-service_kdump_disabled_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>74 ······</ocil:actions>
105 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·No·World-Writable·Files·Exist</ocil:title>77 ······<ocil:title>System·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>
108 ······<ocil:actions>78 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_world_writable_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>80 ······</ocil:actions>
111 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-package_rsync_removed_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">
113 ······<ocil:title>Uninstall·rsync·Package</ocil:title>83 ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>
114 ······<ocil:actions>84 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-package_rsync_removed_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>86 ······</ocil:actions>
117 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·auditd·Collects·Unauthorized·Access·Attempts·to·Files·(unsuccessful)</ocil:title>89 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title>
120 ······<ocil:actions>90 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>92 ······</ocil:actions>
123 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_weekly_ocil:questionnaire:1">
125 ······<ocil:title>Set·SSH·Client·Alive·Count·Max·to·zero</ocil:title>95 ······<ocil:title>Verify·Group·Who·Owns·cron.weekly</ocil:title>
Max diff block lines reached; 1776660/1788472 bytes (99.34%) of diff not shown.
1.88 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml
1.88 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml
    
Offset 21, 27 lines modifiedOffset 21, 27 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.15-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.15-patch.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.15-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.15-patch.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:15">30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:15">
31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·15</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·15</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:15">34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:15">
35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·15</cpe-dict:title>35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·15</cpe-dict:title>
36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>
37 ······</cpe-dict:cpe-item>37 ······</cpe-dict:cpe-item>
38 ····</cpe-dict:cpe-list>38 ····</cpe-dict:cpe-list>
39 ··</ds:component>39 ··</ds:component>
40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-xccdf.xml"·timestamp="2025-02-28T20:08:00">40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-xccdf.xml"·timestamp="2025-03-01T22:08:00">
41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-15"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-15"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·15</xccdf-1.2:title>43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·15</xccdf-1.2:title>
44 ······<xccdf-1.2:description>44 ······<xccdf-1.2:description>
45 ········This·guide·presents·a·catalog·of·security-relevant45 ········This·guide·presents·a·catalog·of·security-relevant
46 configuration·settings·for·SUSE·Linux·Enterprise·15.·It·is·a·rendering·of46 configuration·settings·for·SUSE·Linux·Enterprise·15.·It·is·a·rendering·of
47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 200277, 15 lines modifiedOffset 200277, 15 lines modified
200277 ··············<xccdf-1.2:check-content-ref·href="ssg-sle15-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>200277 ··············<xccdf-1.2:check-content-ref·href="ssg-sle15-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
200278 ············</xccdf-1.2:check>200278 ············</xccdf-1.2:check>
200279 ··········</xccdf-1.2:Rule>200279 ··········</xccdf-1.2:Rule>
200280 ········</xccdf-1.2:Group>200280 ········</xccdf-1.2:Group>
200281 ······</xccdf-1.2:Group>200281 ······</xccdf-1.2:Group>
200282 ····</xccdf-1.2:Benchmark>200282 ····</xccdf-1.2:Benchmark>
200283 ··</ds:component>200283 ··</ds:component>
200284 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-oval.xml"·timestamp="2025-02-28T20:08:00">200284 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-oval.xml"·timestamp="2025-03-01T22:08:00">
200285 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">200285 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
200286 ······<oval-def:generator>200286 ······<oval-def:generator>
200287 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>200287 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
200288 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>200288 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
200289 ········<oval:schema_version>5.11</oval:schema_version>200289 ········<oval:schema_version>5.11</oval:schema_version>
200290 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>200290 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
200291 ······</oval-def:generator>200291 ······</oval-def:generator>
Offset 242596, 9925 lines modifiedOffset 242596, 9925 lines modified
242596 ············</oval-def:arithmetic>242596 ············</oval-def:arithmetic>
242597 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>242597 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
242598 ··········</oval-def:arithmetic>242598 ··········</oval-def:arithmetic>
242599 ········</oval-def:local_variable>242599 ········</oval-def:local_variable>
242600 ······</oval-def:variables>242600 ······</oval-def:variables>
242601 ····</oval-def:oval_definitions>242601 ····</oval-def:oval_definitions>
242602 ··</ds:component>242602 ··</ds:component>
242603 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-ocil.xml"·timestamp="2025-02-28T20:08:00">242603 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-ocil.xml"·timestamp="2025-03-01T22:08:00">
242604 ····<ocil:ocil>242604 ····<ocil:ocil>
242605 ······<ocil:generator>242605 ······<ocil:generator>
242606 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>242606 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
242607 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>242607 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
242608 ········<ocil:schema_version>2.0</ocil:schema_version>242608 ········<ocil:schema_version>2.0</ocil:schema_version>
242609 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>242609 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
242610 ······</ocil:generator>242610 ······</ocil:generator>
242611 ······<ocil:questionnaires>242611 ······<ocil:questionnaires>
242612 ········<ocil:questionnaire·id="ocil:ssg-service_debug-shell_disabled_ocil:questionnaire:1"> 
242613 ··········<ocil:title>Disable·debug-shell·SystemD·Service</ocil:title> 
242614 ··········<ocil:actions> 
242615 ············<ocil:test_action_ref>ocil:ssg-service_debug-shell_disabled_action:testaction:1</ocil:test_action_ref> 
242616 ··········</ocil:actions> 
242617 ········</ocil:questionnaire> 
242618 ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_nodev_ocil:questionnaire:1">242612 ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_nodev_ocil:questionnaire:1">
242619 ··········<ocil:title>Add·nodev·Option·to·/var/tmp</ocil:title>242613 ··········<ocil:title>Add·nodev·Option·to·/var/tmp</ocil:title>
242620 ··········<ocil:actions>242614 ··········<ocil:actions>
242621 ············<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_nodev_action:testaction:1</ocil:test_action_ref>242615 ············<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_nodev_action:testaction:1</ocil:test_action_ref>
242622 ··········</ocil:actions>242616 ··········</ocil:actions>
242623 ········</ocil:questionnaire>242617 ········</ocil:questionnaire>
242624 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_vdso_ocil:questionnaire:1">242618 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1">
242625 ··········<ocil:title>Disable·the·32-bit·vDSO</ocil:title>242619 ··········<ocil:title>Set·SSH·Client·Alive·Interval</ocil:title>
242626 ··········<ocil:actions>242620 ··········<ocil:actions>
242627 ············<ocil:test_action_ref>ocil:ssg-kernel_config_compat_vdso_action:testaction:1</ocil:test_action_ref>242621 ············<ocil:test_action_ref>ocil:ssg-sshd_set_idle_timeout_action:testaction:1</ocil:test_action_ref>
242628 ··········</ocil:actions>242622 ··········</ocil:actions>
242629 ········</ocil:questionnaire>242623 ········</ocil:questionnaire>
242630 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">242624 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_ocil:questionnaire:1">
242631 ··········<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>242625 ··········<ocil:title>Limit·CPU·consumption·of·the·Perf·system</ocil:title>
242632 ··········<ocil:actions>242626 ··········<ocil:actions>
242633 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>242627 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_action:testaction:1</ocil:test_action_ref>
242634 ··········</ocil:actions>242628 ··········</ocil:actions>
242635 ········</ocil:questionnaire>242629 ········</ocil:questionnaire>
242636 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1"> 
242637 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>242630 ········<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1">
 242631 ··········<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title>
242638 ··········<ocil:actions>242632 ··········<ocil:actions>
242639 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref>242633 ············<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref>
242640 ··········</ocil:actions>242634 ··········</ocil:actions>
242641 ········</ocil:questionnaire>242635 ········</ocil:questionnaire>
242642 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_ocil:questionnaire:1"> 
242643 ··········<ocil:title>Configure·Accepting·Default·Router·in·Router·Advertisements·on·All·IPv6·Interfaces</ocil:title>242636 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sudoers_ocil:questionnaire:1">
 242637 ··········<ocil:title>Verify·Group·Who·Owns·/etc/sudoers·File</ocil:title>
242644 ··········<ocil:actions>242638 ··········<ocil:actions>
242645 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_action:testaction:1</ocil:test_action_ref>242639 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sudoers_action:testaction:1</ocil:test_action_ref>
242646 ··········</ocil:actions>242640 ··········</ocil:actions>
242647 ········</ocil:questionnaire>242641 ········</ocil:questionnaire>
242648 ········<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">242642 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1">
242649 ··········<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>242643 ··········<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title>
242650 ··········<ocil:actions>242644 ··········<ocil:actions>
242651 ············<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>242645 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>
242652 ··········</ocil:actions>242646 ··········</ocil:actions>
242653 ········</ocil:questionnaire>242647 ········</ocil:questionnaire>
242654 ········<ocil:questionnaire·id="ocil:ssg-package_setroubleshoot-plugins_removed_ocil:questionnaire:1">242648 ········<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1">
242655 ··········<ocil:title>Uninstall·setroubleshoot-plugins·Package</ocil:title>242649 ··········<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title>
242656 ··········<ocil:actions>242650 ··········<ocil:actions>
242657 ············<ocil:test_action_ref>ocil:ssg-package_setroubleshoot-plugins_removed_action:testaction:1</ocil:test_action_ref>242651 ············<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref>
242658 ··········</ocil:actions>242652 ··········</ocil:actions>
242659 ········</ocil:questionnaire>242653 ········</ocil:questionnaire>
242660 ········<ocil:questionnaire·id="ocil:ssg-rpm_verify_permissions_ocil:questionnaire:1">242654 ········<ocil:questionnaire·id="ocil:ssg-installed_OS_is_vendor_supported_ocil:questionnaire:1">
242661 ··········<ocil:title>Verify·and·Correct·File·Permissions·with·RPM</ocil:title>242655 ··········<ocil:title>The·Installed·Operating·System·Is·Vendor·Supported</ocil:title>
242662 ··········<ocil:actions>242656 ··········<ocil:actions>
242663 ············<ocil:test_action_ref>ocil:ssg-rpm_verify_permissions_action:testaction:1</ocil:test_action_ref>242657 ············<ocil:test_action_ref>ocil:ssg-installed_OS_is_vendor_supported_action:testaction:1</ocil:test_action_ref>
242664 ··········</ocil:actions>242658 ··········</ocil:actions>
242665 ········</ocil:questionnaire>242659 ········</ocil:questionnaire>
242666 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_set_min_life_existing_ocil:questionnaire:1">242660 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1">
242667 ··········<ocil:title>Set·Existing·Passwords·Minimum·Age</ocil:title>242661 ··········<ocil:title>Disable·IA32·emulation</ocil:title>
242668 ··········<ocil:actions>242662 ··········<ocil:actions>
242669 ············<ocil:test_action_ref>ocil:ssg-accounts_password_set_min_life_existing_action:testaction:1</ocil:test_action_ref>242663 ············<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref>
242670 ··········</ocil:actions>242664 ··········</ocil:actions>
242671 ········</ocil:questionnaire>242665 ········</ocil:questionnaire>
242672 ········<ocil:questionnaire·id="ocil:ssg-set_nftables_table_ocil:questionnaire:1">242666 ········<ocil:questionnaire·id="ocil:ssg-no_files_unowned_by_user_ocil:questionnaire:1">
242673 ··········<ocil:title>Ensure·a·Table·Exists·for·Nftables</ocil:title>242667 ··········<ocil:title>Ensure·All·Files·Are·Owned·by·a·User</ocil:title>
242674 ··········<ocil:actions>242668 ··········<ocil:actions>
242675 ············<ocil:test_action_ref>ocil:ssg-set_nftables_table_action:testaction:1</ocil:test_action_ref>242669 ············<ocil:test_action_ref>ocil:ssg-no_files_unowned_by_user_action:testaction:1</ocil:test_action_ref>
242676 ··········</ocil:actions>242670 ··········</ocil:actions>
Max diff block lines reached; 1958675/1970342 bytes (99.41%) of diff not shown.
1.8 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ocil.xml
1.8 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ocil.xml
Ordering differences only
    
Offset 3, 9916 lines modifiedOffset 3, 9916 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-service_debug-shell_disabled_ocil:questionnaire:1"> 
11 ······<ocil:title>Disable·debug-shell·SystemD·Service</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-service_debug-shell_disabled_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_nodev_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_nodev_ocil:questionnaire:1">
17 ······<ocil:title>Add·nodev·Option·to·/var/tmp</ocil:title>11 ······<ocil:title>Add·nodev·Option·to·/var/tmp</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_nodev_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_nodev_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_vdso_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1">
23 ······<ocil:title>Disable·the·32-bit·vDSO</ocil:title>17 ······<ocil:title>Set·SSH·Client·Alive·Interval</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_compat_vdso_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sshd_set_idle_timeout_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1"> 
29 ······<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_ocil:questionnaire:1">
 23 ······<ocil:title>Limit·CPU·consumption·of·the·Perf·system</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1"> 
35 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1">
 29 ······<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_ocil:questionnaire:1"> 
41 ······<ocil:title>Configure·Accepting·Default·Router·in·Router·Advertisements·on·All·IPv6·Interfaces</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sudoers_ocil:questionnaire:1">
 35 ······<ocil:title>Verify·Group·Who·Owns·/etc/sudoers·File</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sudoers_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>41 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-package_setroubleshoot-plugins_removed_ocil:questionnaire:1"> 
53 ······<ocil:title>Uninstall·setroubleshoot-plugins·Package</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1">
 47 ······<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-package_setroubleshoot-plugins_removed_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_permissions_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-installed_OS_is_vendor_supported_ocil:questionnaire:1">
59 ······<ocil:title>Verify·and·Correct·File·Permissions·with·RPM</ocil:title>53 ······<ocil:title>The·Installed·Operating·System·Is·Vendor·Supported</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-rpm_verify_permissions_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-installed_OS_is_vendor_supported_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_min_life_existing_ocil:questionnaire:1"> 
65 ······<ocil:title>Set·Existing·Passwords·Minimum·Age</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1">
 59 ······<ocil:title>Disable·IA32·emulation</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_min_life_existing_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-set_nftables_table_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-no_files_unowned_by_user_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·a·Table·Exists·for·Nftables</ocil:title>65 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·User</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-set_nftables_table_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-no_files_unowned_by_user_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_group_ocil:questionnaire:1"> 
77 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/group</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sestatus_conf_ocil:questionnaire:1">
 71 ······<ocil:title>Verify·Group·Who·Owns·/etc/sestatus.conf·File</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_group_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1"> 
83 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_noexec_ocil:questionnaire:1">
 77 ······<ocil:title>Add·noexec·Option·to·/boot</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_noexec_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_requiretty_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_tally2_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·requiretty</ocil:title>83 ······<ocil:title>Set·Deny·For·Failed·Password·Attempts</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sudo_add_requiretty_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_tally2_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1">
95 ······<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>89 ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Root</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_ownership_audit_configuration_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-ensure_pam_wheel_group_empty_ocil:questionnaire:1"> 
101 ······<ocil:title>Ensure·the·Group·Used·by·pam_wheel.so·Module·Exists·on·System·and·is·Empty</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1">
 95 ······<ocil:title>Ensure·rsyslog·is·Installed</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-ensure_pam_wheel_group_empty_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-is_fips_mode_enabled_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlinkat_ocil:questionnaire:1">
107 ······<ocil:title>Verify·'/proc/sys/crypto/fips_enabled'·exists</ocil:title>101 ······<ocil:title>Record·Unsuccessful·Delete·Attempts·to·Files·-·unlinkat</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-is_fips_mode_enabled_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_unlinkat_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_forwarding_ocil:questionnaire:1"> 
113 ······<ocil:title>Disable·Kernel·Parameter·for·IPv6·Forwarding·by·default</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_group_ownership_ocil:questionnaire:1">
 107 ······<ocil:title>User·Initialization·Files·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_forwarding_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-accounts_user_dot_group_ownership_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_sudo_log_events_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-package_setroubleshoot-server_removed_ocil:questionnaire:1">
119 ······<ocil:title>Record·Attempts·to·perform·maintenance·activities</ocil:title>113 ······<ocil:title>Uninstall·setroubleshoot-server·Package</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
Max diff block lines reached; 1872949/1884884 bytes (99.37%) of diff not shown.
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ds.xml
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ds.xml
    
Offset 21, 15 lines modifiedOffset 21, 15 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.micro.5-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.micro.5-patch.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.micro.5-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.micro.5-patch.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.3">30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.3">
31 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.3</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.3</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.4">34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.4">
35 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.4</cpe-dict:title>35 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.4</cpe-dict:title>
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 ······</cpe-dict:cpe-item>41 ······</cpe-dict:cpe-item>
42 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-microos:5.2">42 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-microos:5.2">
43 ········<cpe-dict:title·xml:lang="en-us">SLE·MicroOS·5.2</cpe-dict:title>43 ········<cpe-dict:title·xml:lang="en-us">SLE·MicroOS·5.2</cpe-dict:title>
44 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>44 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>
45 ······</cpe-dict:cpe-item>45 ······</cpe-dict:cpe-item>
46 ····</cpe-dict:cpe-list>46 ····</cpe-dict:cpe-list>
47 ··</ds:component>47 ··</ds:component>
48 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-xccdf.xml"·timestamp="2025-02-28T20:08:00">48 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-xccdf.xml"·timestamp="2025-03-01T22:08:00">
49 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLMICRO5"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">49 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLMICRO5"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
50 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>50 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
51 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·Micro·5</xccdf-1.2:title>51 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·Micro·5</xccdf-1.2:title>
52 ······<xccdf-1.2:description>52 ······<xccdf-1.2:description>
53 ········This·guide·presents·a·catalog·of·security-relevant53 ········This·guide·presents·a·catalog·of·security-relevant
54 configuration·settings·for·SUSE·Linux·Enterprise·Micro·5.·It·is·a·rendering·of54 configuration·settings·for·SUSE·Linux·Enterprise·Micro·5.·It·is·a·rendering·of
55 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)55 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 124816, 15 lines modifiedOffset 124816, 15 lines modified
124816 ··············<xccdf-1.2:check-content-ref·href="ssg-slmicro5-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_percentage_ocil:questionnaire:1"/>124816 ··············<xccdf-1.2:check-content-ref·href="ssg-slmicro5-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_percentage_ocil:questionnaire:1"/>
124817 ············</xccdf-1.2:check>124817 ············</xccdf-1.2:check>
124818 ··········</xccdf-1.2:Rule>124818 ··········</xccdf-1.2:Rule>
124819 ········</xccdf-1.2:Group>124819 ········</xccdf-1.2:Group>
124820 ······</xccdf-1.2:Group>124820 ······</xccdf-1.2:Group>
124821 ····</xccdf-1.2:Benchmark>124821 ····</xccdf-1.2:Benchmark>
124822 ··</ds:component>124822 ··</ds:component>
124823 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-oval.xml"·timestamp="2025-02-28T20:08:00">124823 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-oval.xml"·timestamp="2025-03-01T22:08:00">
124824 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">124824 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
124825 ······<oval-def:generator>124825 ······<oval-def:generator>
124826 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>124826 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
124827 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>124827 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version>
124828 ········<oval:schema_version>5.11</oval:schema_version>124828 ········<oval:schema_version>5.11</oval:schema_version>
124829 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>124829 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
124830 ······</oval-def:generator>124830 ······</oval-def:generator>
Offset 146446, 5421 lines modifiedOffset 146446, 5421 lines modified
146446 ············</oval-def:arithmetic>146446 ············</oval-def:arithmetic>
146447 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>146447 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
146448 ··········</oval-def:arithmetic>146448 ··········</oval-def:arithmetic>
146449 ········</oval-def:local_variable>146449 ········</oval-def:local_variable>
146450 ······</oval-def:variables>146450 ······</oval-def:variables>
146451 ····</oval-def:oval_definitions>146451 ····</oval-def:oval_definitions>
146452 ··</ds:component>146452 ··</ds:component>
146453 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"·timestamp="2025-02-28T20:08:00">146453 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"·timestamp="2025-03-01T22:08:00">
146454 ····<ocil:ocil>146454 ····<ocil:ocil>
146455 ······<ocil:generator>146455 ······<ocil:generator>
146456 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>146456 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
146457 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>146457 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
146458 ········<ocil:schema_version>2.0</ocil:schema_version>146458 ········<ocil:schema_version>2.0</ocil:schema_version>
146459 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>146459 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
146460 ······</ocil:generator>146460 ······</ocil:generator>
146461 ······<ocil:questionnaires>146461 ······<ocil:questionnaires>
146462 ········<ocil:questionnaire·id="ocil:ssg-chronyd_or_ntpd_set_maxpoll_ocil:questionnaire:1">146462 ········<ocil:questionnaire·id="ocil:ssg-service_xinetd_disabled_ocil:questionnaire:1">
 146463 ··········<ocil:title>Disable·xinetd·Service</ocil:title>
146463 ··········<ocil:title>Configure·Time·Service·Maxpoll·Interval</ocil:title> 
146464 ··········<ocil:actions> 
146465 ············<ocil:test_action_ref>ocil:ssg-chronyd_or_ntpd_set_maxpoll_action:testaction:1</ocil:test_action_ref> 
146466 ··········</ocil:actions> 
146467 ········</ocil:questionnaire> 
146468 ········<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1"> 
146469 ··········<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title> 
146470 ··········<ocil:actions>146464 ··········<ocil:actions>
146471 ············<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>146465 ············<ocil:test_action_ref>ocil:ssg-service_xinetd_disabled_action:testaction:1</ocil:test_action_ref>
146472 ··········</ocil:actions>146466 ··········</ocil:actions>
146473 ········</ocil:questionnaire>146467 ········</ocil:questionnaire>
146474 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1"> 
146475 ··········<ocil:title>Verify·User·Who·Owns·Backup·passwd·File</ocil:title>146468 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">
 146469 ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
146476 ··········<ocil:actions>146470 ··········<ocil:actions>
146477 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>146471 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>
146478 ··········</ocil:actions>146472 ··········</ocil:actions>
146479 ········</ocil:questionnaire>146473 ········</ocil:questionnaire>
146480 ········<ocil:questionnaire·id="ocil:ssg-package_talk_removed_ocil:questionnaire:1">146474 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1">
146481 ··········<ocil:title>Uninstall·talk·Package</ocil:title>146475 ··········<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title>
146482 ··········<ocil:actions>146476 ··········<ocil:actions>
146483 ············<ocil:test_action_ref>ocil:ssg-package_talk_removed_action:testaction:1</ocil:test_action_ref>146477 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref>
146484 ··········</ocil:actions>146478 ··········</ocil:actions>
146485 ········</ocil:questionnaire>146479 ········</ocil:questionnaire>
146486 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1"> 
146487 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>146480 ········<ocil:questionnaire·id="ocil:ssg-service_nftables_enabled_ocil:questionnaire:1">
 146481 ··········<ocil:title>Verify·nftables·Service·is·Enabled</ocil:title>
146488 ··········<ocil:actions>146482 ··········<ocil:actions>
146489 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>146483 ············<ocil:test_action_ref>ocil:ssg-service_nftables_enabled_action:testaction:1</ocil:test_action_ref>
146490 ··········</ocil:actions>146484 ··········</ocil:actions>
146491 ········</ocil:questionnaire>146485 ········</ocil:questionnaire>
146492 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1">146486 ········<ocil:questionnaire·id="ocil:ssg-journald_storage_ocil:questionnaire:1">
146493 ··········<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title>146487 ··········<ocil:title>Ensure·journald·is·configured·to·write·log·files·to·persistent·disk</ocil:title>
146494 ··········<ocil:actions>146488 ··········<ocil:actions>
146495 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref>146489 ············<ocil:test_action_ref>ocil:ssg-journald_storage_action:testaction:1</ocil:test_action_ref>
146496 ··········</ocil:actions>146490 ··········</ocil:actions>
146497 ········</ocil:questionnaire>146491 ········</ocil:questionnaire>
146498 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">146492 ········<ocil:questionnaire·id="ocil:ssg-package_squid_removed_ocil:questionnaire:1">
146499 ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>146493 ··········<ocil:title>Uninstall·squid·Package</ocil:title>
146500 ··········<ocil:actions>146494 ··········<ocil:actions>
146501 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>146495 ············<ocil:test_action_ref>ocil:ssg-package_squid_removed_action:testaction:1</ocil:test_action_ref>
146502 ··········</ocil:actions>146496 ··········</ocil:actions>
146503 ········</ocil:questionnaire>146497 ········</ocil:questionnaire>
146504 ········<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_ciphers_ordered_stig_ocil:questionnaire:1"> 
146505 ··········<ocil:title>Use·Only·FIPS·140-2·Validated·Ciphers</ocil:title>146498 ········<ocil:questionnaire·id="ocil:ssg-auditd_audispd_network_failure_action_ocil:questionnaire:1">
 146499 ··········<ocil:title>Configure·audispd's·Plugin·network_failure_action·On·Network·Failure</ocil:title>
146506 ··········<ocil:actions>146500 ··········<ocil:actions>
146507 ············<ocil:test_action_ref>ocil:ssg-sshd_use_approved_ciphers_ordered_stig_action:testaction:1</ocil:test_action_ref>146501 ············<ocil:test_action_ref>ocil:ssg-auditd_audispd_network_failure_action_action:testaction:1</ocil:test_action_ref>
146508 ··········</ocil:actions>146502 ··········</ocil:actions>
146509 ········</ocil:questionnaire>146503 ········</ocil:questionnaire>
146510 ········<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1"> 
146511 ··········<ocil:title>Set·PAM''s·Password·Hashing·Algorithm</ocil:title>146504 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1">
 146505 ··········<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title>
146512 ··········<ocil:actions>146506 ··········<ocil:actions>
146513 ············<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref>146507 ············<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref>
146514 ··········</ocil:actions>146508 ··········</ocil:actions>
146515 ········</ocil:questionnaire>146509 ········</ocil:questionnaire>
146516 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1"> 
146517 ··········<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>146510 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1">
 146511 ··········<ocil:title>Ensure·All·Files·Are·Owned·by·a·Group</ocil:title>
146518 ··········<ocil:actions>146512 ··········<ocil:actions>
Max diff block lines reached; 1047462/1059077 bytes (98.90%) of diff not shown.
988 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ocil.xml
988 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ocil.xml
Ordering differences only
    
Offset 3, 5412 lines modifiedOffset 3, 5412 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-chronyd_or_ntpd_set_maxpoll_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-service_xinetd_disabled_ocil:questionnaire:1">
 11 ······<ocil:title>Disable·xinetd·Service</ocil:title>
11 ······<ocil:title>Configure·Time·Service·Maxpoll·Interval</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-chronyd_or_ntpd_set_maxpoll_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1"> 
17 ······<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-service_xinetd_disabled_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1"> 
23 ······<ocil:title>Verify·User·Who·Owns·Backup·passwd·File</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">
 17 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-package_talk_removed_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1">
29 ······<ocil:title>Uninstall·talk·Package</ocil:title>23 ······<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-package_talk_removed_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1"> 
35 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-service_nftables_enabled_ocil:questionnaire:1">
 29 ······<ocil:title>Verify·nftables·Service·is·Enabled</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-service_nftables_enabled_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-journald_storage_ocil:questionnaire:1">
41 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title>35 ······<ocil:title>Ensure·journald·is·configured·to·write·log·files·to·persistent·disk</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-journald_storage_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-package_squid_removed_ocil:questionnaire:1">
47 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>41 ······<ocil:title>Uninstall·squid·Package</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-package_squid_removed_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_ciphers_ordered_stig_ocil:questionnaire:1"> 
53 ······<ocil:title>Use·Only·FIPS·140-2·Validated·Ciphers</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_network_failure_action_ocil:questionnaire:1">
 47 ······<ocil:title>Configure·audispd's·Plugin·network_failure_action·On·Network·Failure</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sshd_use_approved_ciphers_ordered_stig_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_network_failure_action_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1"> 
59 ······<ocil:title>Set·PAM''s·Password·Hashing·Algorithm</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1">
 53 ······<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1"> 
65 ······<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1">
 59 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·Group</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_ungroupowned_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-aide_build_database_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-package_talk_removed_ocil:questionnaire:1">
71 ······<ocil:title>Build·and·Test·AIDE·Database</ocil:title>65 ······<ocil:title>Uninstall·talk·Package</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-aide_build_database_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-package_talk_removed_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-require_emergency_target_auth_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">
77 ······<ocil:title>Require·Authentication·for·Emergency·Systemd·Target</ocil:title>71 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-require_emergency_target_auth_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-cracklib_accounts_password_pam_minlen_ocil:questionnaire:1">
83 ······<ocil:title>Prevent·Login·to·Accounts·With·Empty·Password</ocil:title>77 ······<ocil:title>Set·Password·Minimum·Length</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-no_empty_passwords_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-cracklib_accounts_password_pam_minlen_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-no_files_unowned_by_user_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-dir_system_commands_root_owned_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·User</ocil:title>83 ······<ocil:title>Verify·that·system·commands·directories·have·root·ownership</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-no_files_unowned_by_user_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-dir_system_commands_root_owned_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_vsftpd_removed_ocil:questionnaire:1"> 
95 ······<ocil:title>Uninstall·vsftpd·Package</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1">
 89 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_vsftpd_removed_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-cracklib_accounts_password_pam_lcredit_ocil:questionnaire:1"> 
101 ······<ocil:title>Set·Password·Strength·Minimum·Lowercase·Characters</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1">
 95 ······<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-cracklib_accounts_password_pam_lcredit_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nosuid_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-display_login_attempts_ocil:questionnaire:1">
107 ······<ocil:title>Add·nosuid·Option·to·/home</ocil:title>101 ······<ocil:title>Ensure·PAM·Displays·Last·Logon/Access·Notification</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nosuid_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-display_login_attempts_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1">
113 ······<ocil:title>Disable·Kernel·Parameter·for·IPv6·Forwarding</ocil:title>107 ······<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-accounts_authorized_local_users_ocil:questionnaire:1"> 
119 ······<ocil:title>Only·Authorized·Local·User·Accounts·Exist·on·Operating·System</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-sudoers_default_includedir_ocil:questionnaire:1">
 113 ······<ocil:title>Ensure·sudo·only·includes·the·default·configuration·directory</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
Max diff block lines reached; 999168/1011373 bytes (98.79%) of diff not shown.