93.7 MB
/srv/reproducible-results/rbuild-debian/r-b-build.Sv2UvbQD/b1/scap-security-guide_0.1.76-1_arm64.changes vs.
/srv/reproducible-results/rbuild-debian/r-b-build.Sv2UvbQD/b2/scap-security-guide_0.1.76-1_arm64.changes
824 B
Files
    
Offset 1, 6 lines modifiedOffset 1, 6 lines modified
  
1 ·5c7fc0861da0724c3b9c581dabb61e59·153736·admin·optional·ssg-applications_0.1.76-1_all.deb1 ·29368b30f466df009e7a66775dd60b9a·153748·admin·optional·ssg-applications_0.1.76-1_all.deb
2 ·ea0c1f19113a8a6c0a6e8b10e8e208a9·32632·admin·optional·ssg-base_0.1.76-1_all.deb2 ·ea0c1f19113a8a6c0a6e8b10e8e208a9·32632·admin·optional·ssg-base_0.1.76-1_all.deb
3 ·7fa024acaab020a5524de10ea54b1961·3725596·admin·optional·ssg-debderived_0.1.76-1_all.deb 
4 ·c75ab2fa0ea0b629f363d3588cd658a2·1232464·admin·optional·ssg-debian_0.1.76-1_all.deb 
5 ·8561079919ce903d0a49f8b3f6dd2760·37100756·admin·optional·ssg-nondebian_0.1.76-1_all.deb3 ·b706962ed402fa46e2d8a483c9aea4f5·3725380·admin·optional·ssg-debderived_0.1.76-1_all.deb
 4 ·13b5ac8064457eed9641b83294552ed4·1232392·admin·optional·ssg-debian_0.1.76-1_all.deb
 5 ·d3cab936bf2112cb82dbda6755bdc811·37100432·admin·optional·ssg-nondebian_0.1.76-1_all.deb
428 KB
ssg-applications_0.1.76-1_all.deb
367 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0·····1728·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1728·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0···151816·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0···151828·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
428 KB
data.tar.xz
428 KB
data.tar
78.7 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
78.6 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:google:chromium-browser">28 ······<cpe-dict:cpe-item·name="cpe:/a:google:chromium-browser">
29 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Chromium.·It·is·a·rendering·of40 configuration·settings·for·Chromium.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 1675, 15 lines modifiedOffset 1675, 15 lines modified
1675 ··········<xccdf-1.2:check·system="http://scap.nist.gov/schema/ocil/2">1675 ··········<xccdf-1.2:check·system="http://scap.nist.gov/schema/ocil/2">
1676 ············<xccdf-1.2:check-content-ref·href="ssg-chromium-ocil.xml"·name="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"/>1676 ············<xccdf-1.2:check-content-ref·href="ssg-chromium-ocil.xml"·name="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"/>
1677 ··········</xccdf-1.2:check>1677 ··········</xccdf-1.2:check>
1678 ········</xccdf-1.2:Rule>1678 ········</xccdf-1.2:Rule>
1679 ······</xccdf-1.2:Group>1679 ······</xccdf-1.2:Group>
1680 ····</xccdf-1.2:Benchmark>1680 ····</xccdf-1.2:Benchmark>
1681 ··</ds:component>1681 ··</ds:component>
1682 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-oval.xml"·timestamp="2025-02-28T20:08:00">1682 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-oval.xml"·timestamp="2025-03-01T22:08:00">
1683 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">1683 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
1684 ······<oval-def:generator>1684 ······<oval-def:generator>
1685 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>1685 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
1686 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>1686 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
1687 ········<oval:schema_version>5.11</oval:schema_version>1687 ········<oval:schema_version>5.11</oval:schema_version>
1688 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>1688 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
1689 ······</oval-def:generator>1689 ······</oval-def:generator>
Offset 2539, 360 lines modifiedOffset 2539, 360 lines modified
2539 ········<oval-def:external_variable·id="oval:ssg-var_enable_encrypted_searching:var:1"·version="1"·datatype="string"·comment="Expected·search·provider·name"/>2539 ········<oval-def:external_variable·id="oval:ssg-var_enable_encrypted_searching:var:1"·version="1"·datatype="string"·comment="Expected·search·provider·name"/>
2540 ········<oval-def:external_variable·id="oval:ssg-var_extension_whitelist:var:1"·version="1"·datatype="string"·comment="Expected·approved·extensions"/>2540 ········<oval-def:external_variable·id="oval:ssg-var_extension_whitelist:var:1"·version="1"·datatype="string"·comment="Expected·approved·extensions"/>
2541 ········<oval-def:external_variable·id="oval:ssg-var_auth_schema:var:1"·version="1"·datatype="string"·comment="Expected·HTTP·authentication·type"/>2541 ········<oval-def:external_variable·id="oval:ssg-var_auth_schema:var:1"·version="1"·datatype="string"·comment="Expected·HTTP·authentication·type"/>
2542 ········<oval-def:external_variable·id="oval:ssg-var_trusted_home_page:var:1"·version="1"·datatype="string"·comment="Expected·home·page"/>2542 ········<oval-def:external_variable·id="oval:ssg-var_trusted_home_page:var:1"·version="1"·datatype="string"·comment="Expected·home·page"/>
2543 ······</oval-def:variables>2543 ······</oval-def:variables>
2544 ····</oval-def:oval_definitions>2544 ····</oval-def:oval_definitions>
2545 ··</ds:component>2545 ··</ds:component>
2546 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-ocil.xml"·timestamp="2025-02-28T20:08:00">2546 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-ocil.xml"·timestamp="2025-03-01T22:08:00">
2547 ····<ocil:ocil>2547 ····<ocil:ocil>
2548 ······<ocil:generator>2548 ······<ocil:generator>
2549 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>2549 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
2550 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>2550 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
2551 ········<ocil:schema_version>2.0</ocil:schema_version>2551 ········<ocil:schema_version>2.0</ocil:schema_version>
2552 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>2552 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
2553 ······</ocil:generator>2553 ······</ocil:generator>
2554 ······<ocil:questionnaires>2554 ······<ocil:questionnaires>
2555 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_incognito_mode_ocil:questionnaire:1">2555 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_saved_passwords_ocil:questionnaire:1">
2556 ··········<ocil:title>Disable·Incognito·Mode</ocil:title>2556 ··········<ocil:title>Disable·Saved·Passwords</ocil:title>
2557 ··········<ocil:actions>2557 ··········<ocil:actions>
2558 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_incognito_mode_action:testaction:1</ocil:test_action_ref>2558 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_saved_passwords_action:testaction:1</ocil:test_action_ref>
2559 ··········</ocil:actions>2559 ··········</ocil:actions>
2560 ········</ocil:questionnaire>2560 ········</ocil:questionnaire>
2561 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_cloud_print_sharing_ocil:questionnaire:1">2561 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_name_ocil:questionnaire:1">
2562 ··········<ocil:title>Disable·Cloud·Print·Sharing</ocil:title>2562 ··········<ocil:title>Set·the·Default·Search·Provider's·URL</ocil:title>
2563 ··········<ocil:actions>2563 ··········<ocil:actions>
2564 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_cloud_print_sharing_action:testaction:1</ocil:test_action_ref>2564 ············<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_name_action:testaction:1</ocil:test_action_ref>
2565 ··········</ocil:actions>2565 ··········</ocil:actions>
2566 ········</ocil:questionnaire>2566 ········</ocil:questionnaire>
2567 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">2567 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">
2568 ··········<ocil:title>Enable·Saving·the·Browser·History</ocil:title>2568 ··········<ocil:title>Disable·Metrics·Reporting</ocil:title>
2569 ··········<ocil:actions>2569 ··········<ocil:actions>
 2570 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>
 2571 ··········</ocil:actions>
 2572 ········</ocil:questionnaire>
 2573 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_google_sync_ocil:questionnaire:1">
 2574 ··········<ocil:title>Disable·Data·Synchronization·to·Google</ocil:title>
 2575 ··········<ocil:actions>
2570 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>2576 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_google_sync_action:testaction:1</ocil:test_action_ref>
2571 ··········</ocil:actions>2577 ··········</ocil:actions>
2572 ········</ocil:questionnaire>2578 ········</ocil:questionnaire>
2573 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1">2579 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1">
2574 ··········<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title>2580 ··········<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title>
2575 ··········<ocil:actions>2581 ··········<ocil:actions>
2576 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref>2582 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref>
2577 ··········</ocil:actions>2583 ··········</ocil:actions>
2578 ········</ocil:questionnaire>2584 ········</ocil:questionnaire>
2579 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">2585 ········<ocil:questionnaire·id="ocil:ssg-chromium_plugins_require_authorization_ocil:questionnaire:1">
2580 ··········<ocil:title>Enable·the·Default·Search·Provider</ocil:title>2586 ··········<ocil:title>Require·Outdated·Plugins·to·be·Authorized</ocil:title>
2581 ··········<ocil:actions>2587 ··········<ocil:actions>
2582 ············<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref>2588 ············<ocil:test_action_ref>ocil:ssg-chromium_plugins_require_authorization_action:testaction:1</ocil:test_action_ref>
2583 ··········</ocil:actions>2589 ··········</ocil:actions>
2584 ········</ocil:questionnaire>2590 ········</ocil:questionnaire>
2585 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_outdated_plugins_ocil:questionnaire:1">2591 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_3d_graphics_api_ocil:questionnaire:1">
2586 ··········<ocil:title>Disable·Outdated·Plugins</ocil:title>2592 ··········<ocil:title>Disable·the·3D·Graphics·APIs</ocil:title>
2587 ··········<ocil:actions>2593 ··········<ocil:actions>
2588 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_outdated_plugins_action:testaction:1</ocil:test_action_ref>2594 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_3d_graphics_api_action:testaction:1</ocil:test_action_ref>
2589 ··········</ocil:actions>2595 ··········</ocil:actions>
2590 ········</ocil:questionnaire>2596 ········</ocil:questionnaire>
2591 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_saved_passwords_ocil:questionnaire:1">2597 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">
2592 ··········<ocil:title>Disable·Saved·Passwords</ocil:title>2598 ··········<ocil:title>Disable·All·Plugins·by·Default</ocil:title>
2593 ··········<ocil:actions>2599 ··········<ocil:actions>
2594 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_saved_passwords_action:testaction:1</ocil:test_action_ref>2600 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref>
2595 ··········</ocil:actions>2601 ··········</ocil:actions>
2596 ········</ocil:questionnaire>2602 ········</ocil:questionnaire>
2597 ········<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1">2603 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_block_plugins_ocil:questionnaire:1">
2598 ··········<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title>2604 ··········<ocil:title>Block·Plugins·by·Default</ocil:title>
2599 ··········<ocil:actions>2605 ··········<ocil:actions>
2600 ············<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref>2606 ············<ocil:test_action_ref>ocil:ssg-chromium_default_block_plugins_action:testaction:1</ocil:test_action_ref>
2601 ··········</ocil:actions>2607 ··········</ocil:actions>
2602 ········</ocil:questionnaire>2608 ········</ocil:questionnaire>
2603 ········<ocil:questionnaire·id="ocil:ssg-chromium_policy_file_ocil:questionnaire:1">2609 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_safe_browsing_ocil:questionnaire:1">
2604 ··········<ocil:title>Ensure·the·Chromium·Policy·Configuration·File·Exists</ocil:title>2610 ··········<ocil:title>Enable·the·Safe·Browsing·Feature</ocil:title>
2605 ··········<ocil:actions>2611 ··········<ocil:actions>
2606 ············<ocil:test_action_ref>ocil:ssg-chromium_policy_file_action:testaction:1</ocil:test_action_ref>2612 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_safe_browsing_action:testaction:1</ocil:test_action_ref>
2607 ··········</ocil:actions>2613 ··········</ocil:actions>
2608 ········</ocil:questionnaire>2614 ········</ocil:questionnaire>
2609 ········<ocil:questionnaire·id="ocil:ssg-chromium_extension_whitelist_ocil:questionnaire:1">2615 ········<ocil:questionnaire·id="ocil:ssg-chromium_http_authentication_ocil:questionnaire:1">
2610 ··········<ocil:title>Enable·Only·Approved·Extensions</ocil:title>2616 ··········<ocil:title>Set·Chromium's·HTTP·Authentication·Scheme</ocil:title>
2611 ··········<ocil:actions>2617 ··········<ocil:actions>
2612 ············<ocil:test_action_ref>ocil:ssg-chromium_extension_whitelist_action:testaction:1</ocil:test_action_ref>2618 ············<ocil:test_action_ref>ocil:ssg-chromium_http_authentication_action:testaction:1</ocil:test_action_ref>
2613 ··········</ocil:actions>2619 ··········</ocil:actions>
2614 ········</ocil:questionnaire>2620 ········</ocil:questionnaire>
2615 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_password_manager_ocil:questionnaire:1">2621 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_session_cookies_ocil:questionnaire:1">
2616 ··········<ocil:title>Disable·Chromium·Password·Manager</ocil:title>2622 ··········<ocil:title>Disable·Session·Cookies</ocil:title>
2617 ··········<ocil:actions>2623 ··········<ocil:actions>
2618 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_password_manager_action:testaction:1</ocil:test_action_ref>2624 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_session_cookies_action:testaction:1</ocil:test_action_ref>
2619 ··········</ocil:actions>2625 ··········</ocil:actions>
Max diff block lines reached; 68300/80346 bytes (85.01%) of diff not shown.
70.1 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ocil.xml
70.0 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ocil.xml
Ordering differences only
    
Offset 3, 351 lines modifiedOffset 3, 351 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_incognito_mode_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_saved_passwords_ocil:questionnaire:1">
11 ······<ocil:title>Disable·Incognito·Mode</ocil:title>11 ······<ocil:title>Disable·Saved·Passwords</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_incognito_mode_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_saved_passwords_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cloud_print_sharing_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_name_ocil:questionnaire:1">
17 ······<ocil:title>Disable·Cloud·Print·Sharing</ocil:title>17 ······<ocil:title>Set·the·Default·Search·Provider's·URL</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cloud_print_sharing_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_name_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">
23 ······<ocil:title>Enable·Saving·the·Browser·History</ocil:title>23 ······<ocil:title>Disable·Metrics·Reporting</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
 25 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>
 26 ······</ocil:actions>
 27 ····</ocil:questionnaire>
 28 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_google_sync_ocil:questionnaire:1">
 29 ······<ocil:title>Disable·Data·Synchronization·to·Google</ocil:title>
 30 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_google_sync_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>32 ······</ocil:actions>
27 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1">
29 ······<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title>35 ······<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title>
30 ······<ocil:actions>36 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>38 ······</ocil:actions>
33 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-chromium_plugins_require_authorization_ocil:questionnaire:1">
35 ······<ocil:title>Enable·the·Default·Search·Provider</ocil:title>41 ······<ocil:title>Require·Outdated·Plugins·to·be·Authorized</ocil:title>
36 ······<ocil:actions>42 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-chromium_plugins_require_authorization_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>44 ······</ocil:actions>
39 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_outdated_plugins_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_3d_graphics_api_ocil:questionnaire:1">
41 ······<ocil:title>Disable·Outdated·Plugins</ocil:title>47 ······<ocil:title>Disable·the·3D·Graphics·APIs</ocil:title>
42 ······<ocil:actions>48 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_outdated_plugins_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_3d_graphics_api_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>50 ······</ocil:actions>
45 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_saved_passwords_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">
47 ······<ocil:title>Disable·Saved·Passwords</ocil:title>53 ······<ocil:title>Disable·All·Plugins·by·Default</ocil:title>
48 ······<ocil:actions>54 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_saved_passwords_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>56 ······</ocil:actions>
51 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_block_plugins_ocil:questionnaire:1">
53 ······<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title>59 ······<ocil:title>Block·Plugins·by·Default</ocil:title>
54 ······<ocil:actions>60 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-chromium_default_block_plugins_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>62 ······</ocil:actions>
57 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-chromium_policy_file_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_safe_browsing_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·the·Chromium·Policy·Configuration·File·Exists</ocil:title>65 ······<ocil:title>Enable·the·Safe·Browsing·Feature</ocil:title>
60 ······<ocil:actions>66 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-chromium_policy_file_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_safe_browsing_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>68 ······</ocil:actions>
63 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-chromium_extension_whitelist_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-chromium_http_authentication_ocil:questionnaire:1">
65 ······<ocil:title>Enable·Only·Approved·Extensions</ocil:title>71 ······<ocil:title>Set·Chromium's·HTTP·Authentication·Scheme</ocil:title>
66 ······<ocil:actions>72 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-chromium_extension_whitelist_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-chromium_http_authentication_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>74 ······</ocil:actions>
69 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_password_manager_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_session_cookies_ocil:questionnaire:1">
71 ······<ocil:title>Disable·Chromium·Password·Manager</ocil:title>77 ······<ocil:title>Disable·Session·Cookies</ocil:title>
72 ······<ocil:actions>78 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_password_manager_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_session_cookies_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>80 ······</ocil:actions>
75 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-chromium_block_desktop_notifications_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_incognito_mode_ocil:questionnaire:1">
77 ······<ocil:title>Prevent·Desktop·Notifications</ocil:title>83 ······<ocil:title>Disable·Incognito·Mode</ocil:title>
78 ······<ocil:actions>84 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-chromium_block_desktop_notifications_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_incognito_mode_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>86 ······</ocil:actions>
81 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_network_prediction_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_network_prediction_ocil:questionnaire:1">
83 ······<ocil:title>Disable·Network·Prediction</ocil:title>89 ······<ocil:title>Disable·Network·Prediction</ocil:title>
84 ······<ocil:actions>90 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_network_prediction_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_network_prediction_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>92 ······</ocil:actions>
87 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1"> 
89 ······<ocil:title>Enable·Only·Approved·Plugins</ocil:title> 
90 ······<ocil:actions> 
91 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref> 
92 ······</ocil:actions> 
93 ····</ocil:questionnaire> 
94 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">
95 ······<ocil:title>Disable·All·Plugins·by·Default</ocil:title>95 ······<ocil:title>Disable·Location·Tracking</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_firewall_traversal_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_firewall_traversal_ocil:questionnaire:1">
101 ······<ocil:title>Disable·Chromium's·Ability·to·Traverse·Firewalls</ocil:title>101 ······<ocil:title>Disable·Chromium's·Ability·to·Traverse·Firewalls</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_firewall_traversal_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_firewall_traversal_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_thirdparty_cookies_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_password_manager_ocil:questionnaire:1">
107 ······<ocil:title>Disable·3rd·Party·Cookies</ocil:title>107 ······<ocil:title>Disable·Chromium·Password·Manager</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_thirdparty_cookies_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_password_manager_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_popups_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_search_suggestions_ocil:questionnaire:1">
113 ······<ocil:title>Disable·Popups</ocil:title>113 ······<ocil:title>Disable·Search·Suggestion</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_popups_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_search_suggestions_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_name_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cleartext_passwords_ocil:questionnaire:1">
119 ······<ocil:title>Set·the·Default·Search·Provider's·URL</ocil:title>119 ······<ocil:title>Disable·Use·of·Cleartext·Passwords</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_name_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cleartext_passwords_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
Max diff block lines reached; 59808/71527 bytes (83.62%) of diff not shown.
91.7 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
91.6 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service:1">28 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service:1">
29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service_node:1.21">32 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service_node:1.21">
33 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·1.21</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·1.21</cpe-dict:title>
Offset 35, 15 lines modifiedOffset 35, 15 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:elastic_kubernetes_service_node:1">36 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:elastic_kubernetes_service_node:1">
37 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2025-02-28T20:08:00">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2025-03-01T22:08:00">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of48 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 1545, 15 lines modifiedOffset 1545, 15 lines modified
1545 ··············<xccdf-1.2:check-content-ref·href="ssg-eks-ocil.xml"·name="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"/>1545 ··············<xccdf-1.2:check-content-ref·href="ssg-eks-ocil.xml"·name="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"/>
1546 ············</xccdf-1.2:check>1546 ············</xccdf-1.2:check>
1547 ··········</xccdf-1.2:Rule>1547 ··········</xccdf-1.2:Rule>
1548 ········</xccdf-1.2:Group>1548 ········</xccdf-1.2:Group>
1549 ······</xccdf-1.2:Group>1549 ······</xccdf-1.2:Group>
1550 ····</xccdf-1.2:Benchmark>1550 ····</xccdf-1.2:Benchmark>
1551 ··</ds:component>1551 ··</ds:component>
1552 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-oval.xml"·timestamp="2025-02-28T20:08:00">1552 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-oval.xml"·timestamp="2025-03-01T22:08:00">
1553 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">1553 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
1554 ······<oval-def:generator>1554 ······<oval-def:generator>
1555 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>1555 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
1556 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>1556 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
1557 ········<oval:schema_version>5.11</oval:schema_version>1557 ········<oval:schema_version>5.11</oval:schema_version>
1558 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>1558 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
1559 ······</oval-def:generator>1559 ······</oval-def:generator>
Offset 2166, 234 lines modifiedOffset 2166, 234 lines modified
2166 ········<oval-def:external_variable·id="oval:ssg-var_streaming_connection_timeouts:var:1"·version="1"·datatype="string"·comment="variable"/>2166 ········<oval-def:external_variable·id="oval:ssg-var_streaming_connection_timeouts:var:1"·version="1"·datatype="string"·comment="variable"/>
2167 ········<oval-def:local_variable·id="oval:ssg-kubelet_read_only_port_secured_file_location:var:1"·version="1"·datatype="string"·comment="The·actual·path·of·the·file·to·scan.">2167 ········<oval-def:local_variable·id="oval:ssg-kubelet_read_only_port_secured_file_location:var:1"·version="1"·datatype="string"·comment="The·actual·path·of·the·file·to·scan.">
2168 ··········<oval-def:literal_component>/etc/kubernetes/compliance-operator/kubeletconfig/openscap-kubeletconfig</oval-def:literal_component>2168 ··········<oval-def:literal_component>/etc/kubernetes/compliance-operator/kubeletconfig/openscap-kubeletconfig</oval-def:literal_component>
2169 ········</oval-def:local_variable>2169 ········</oval-def:local_variable>
2170 ······</oval-def:variables>2170 ······</oval-def:variables>
2171 ····</oval-def:oval_definitions>2171 ····</oval-def:oval_definitions>
2172 ··</ds:component>2172 ··</ds:component>
2173 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-ocil.xml"·timestamp="2025-02-28T20:08:00">2173 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-ocil.xml"·timestamp="2025-03-01T22:08:00">
2174 ····<ocil:ocil>2174 ····<ocil:ocil>
2175 ······<ocil:generator>2175 ······<ocil:generator>
2176 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>2176 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
2177 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>2177 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
2178 ········<ocil:schema_version>2.0</ocil:schema_version>2178 ········<ocil:schema_version>2.0</ocil:schema_version>
2179 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>2179 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
2180 ······</ocil:generator>2180 ······</ocil:generator>
2181 ······<ocil:questionnaires>2181 ······<ocil:questionnaires>
2182 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_defaults_ocil:questionnaire:1">2182 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1">
2183 ··········<ocil:title>kubelet·-·Enable·Protect·Kernel·Defaults</ocil:title>2183 ··········<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>
2184 ··········<ocil:actions>2184 ··········<ocil:actions>
2185 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_protect_kernel_defaults_action:testaction:1</ocil:test_action_ref>2185 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>
2186 ··········</ocil:actions>2186 ··········</ocil:actions>
2187 ········</ocil:questionnaire>2187 ········</ocil:questionnaire>
2188 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1"> 
2189 ··········<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>2188 ········<ocil:questionnaire·id="ocil:ssg-control_plane_access_ocil:questionnaire:1">
 2189 ··········<ocil:title>Restrict·Access·to·the·Control·Plane·Endpoint</ocil:title>
2190 ··········<ocil:actions>2190 ··········<ocil:actions>
2191 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref>2191 ············<ocil:test_action_ref>ocil:ssg-control_plane_access_action:testaction:1</ocil:test_action_ref>
2192 ··········</ocil:actions>2192 ··········</ocil:actions>
2193 ········</ocil:questionnaire>2193 ········</ocil:questionnaire>
2194 ········<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1">2194 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1">
2195 ··········<ocil:title>Ensure·Private·Endpoint·Access</ocil:title>2195 ··········<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
2196 ··········<ocil:actions>2196 ··········<ocil:actions>
2197 ············<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref>2197 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref>
2198 ··········</ocil:actions>2198 ··········</ocil:actions>
2199 ········</ocil:questionnaire>2199 ········</ocil:questionnaire>
2200 ········<ocil:questionnaire·id="ocil:ssg-dedicated_service_accounts_ocil:questionnaire:1">2200 ········<ocil:questionnaire·id="ocil:ssg-dedicated_service_accounts_ocil:questionnaire:1">
2201 ··········<ocil:title>Use·Dedicated·Service·Accounts</ocil:title>2201 ··········<ocil:title>Use·Dedicated·Service·Accounts</ocil:title>
2202 ··········<ocil:actions>2202 ··········<ocil:actions>
2203 ············<ocil:test_action_ref>ocil:ssg-dedicated_service_accounts_action:testaction:1</ocil:test_action_ref>2203 ············<ocil:test_action_ref>ocil:ssg-dedicated_service_accounts_action:testaction:1</ocil:test_action_ref>
2204 ··········</ocil:actions>2204 ··········</ocil:actions>
2205 ········</ocil:questionnaire>2205 ········</ocil:questionnaire>
2206 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1">2206 ········<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_conf_ocil:questionnaire:1">
2207 ··········<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title>2207 ··········<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
2208 ··········<ocil:actions>2208 ··········<ocil:actions>
2209 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref>2209 ············<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref>
2210 ··········</ocil:actions>2210 ··········</ocil:actions>
2211 ········</ocil:questionnaire>2211 ········</ocil:questionnaire>
2212 ········<ocil:questionnaire·id="ocil:ssg-configure_network_policies_namespaces_ocil:questionnaire:1">2212 ········<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1">
2213 ··········<ocil:title>Ensure·that·application·Namespaces·have·Network·Policies·defined.</ocil:title>2213 ··········<ocil:title>Ensure·Private·Endpoint·Access</ocil:title>
2214 ··········<ocil:actions>2214 ··········<ocil:actions>
2215 ············<ocil:test_action_ref>ocil:ssg-configure_network_policies_namespaces_action:testaction:1</ocil:test_action_ref>2215 ············<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref>
2216 ··········</ocil:actions>2216 ··········</ocil:actions>
2217 ········</ocil:questionnaire>2217 ········</ocil:questionnaire>
2218 ········<ocil:questionnaire·id="ocil:ssg-registry_access_ocil:questionnaire:1">2218 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_client_cert_rotation_ocil:questionnaire:1">
2219 ··········<ocil:title>Minimize·user·access·to·Amazon·ECR</ocil:title>2219 ··········<ocil:title>kubelet·-·Enable·Client·Certificate·Rotation</ocil:title>
2220 ··········<ocil:actions>2220 ··········<ocil:actions>
2221 ············<ocil:test_action_ref>ocil:ssg-registry_access_action:testaction:1</ocil:test_action_ref>2221 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_client_cert_rotation_action:testaction:1</ocil:test_action_ref>
2222 ··········</ocil:actions>2222 ··········</ocil:actions>
2223 ········</ocil:questionnaire>2223 ········</ocil:questionnaire>
2224 ········<ocil:questionnaire·id="ocil:ssg-fargate_ocil:questionnaire:1">2224 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_ocil:questionnaire:1">
2225 ··········<ocil:title>Consider·Fargate·for·Untrusted·Workloads</ocil:title>2225 ··········<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>
2226 ··········<ocil:actions>2226 ··········<ocil:actions>
2227 ············<ocil:test_action_ref>ocil:ssg-fargate_action:testaction:1</ocil:test_action_ref>2227 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_action:testaction:1</ocil:test_action_ref>
2228 ··········</ocil:actions>2228 ··········</ocil:actions>
2229 ········</ocil:questionnaire>2229 ········</ocil:questionnaire>
2230 ········<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_conf_ocil:questionnaire:1">2230 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">
2231 ··········<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title>2231 ··········<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>
2232 ··········<ocil:actions>2232 ··········<ocil:actions>
2233 ············<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref>2233 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>
2234 ··········</ocil:actions>2234 ··········</ocil:actions>
2235 ········</ocil:questionnaire>2235 ········</ocil:questionnaire>
2236 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_kubelet_conf_ocil:questionnaire:1">2236 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_defaults_ocil:questionnaire:1">
2237 ··········<ocil:title>Verify·Permissions·on·The·Kubelet·Configuration·File</ocil:title>2237 ··········<ocil:title>kubelet·-·Enable·Protect·Kernel·Defaults</ocil:title>
2238 ··········<ocil:actions>2238 ··········<ocil:actions>
2239 ············<ocil:test_action_ref>ocil:ssg-file_permissions_kubelet_conf_action:testaction:1</ocil:test_action_ref>2239 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_protect_kernel_defaults_action:testaction:1</ocil:test_action_ref>
2240 ··········</ocil:actions>2240 ··········</ocil:actions>
2241 ········</ocil:questionnaire>2241 ········</ocil:questionnaire>
2242 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">2242 ········<ocil:questionnaire·id="ocil:ssg-audit_logging_ocil:questionnaire:1">
2243 ··········<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>2243 ··········<ocil:title>Ensure·Audit·Logging·is·Enabled</ocil:title>
Max diff block lines reached; 81749/93676 bytes (87.27%) of diff not shown.
83.1 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ocil.xml
83.0 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ocil.xml
Ordering differences only
    
Offset 3, 225 lines modifiedOffset 3, 225 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_defaults_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1">
11 ······<ocil:title>kubelet·-·Enable·Protect·Kernel·Defaults</ocil:title>11 ······<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_protect_kernel_defaults_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1"> 
17 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-control_plane_access_ocil:questionnaire:1">
 17 ······<ocil:title>Restrict·Access·to·the·Control·Plane·Endpoint</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-control_plane_access_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·Private·Endpoint·Access</ocil:title>23 ······<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-dedicated_service_accounts_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-dedicated_service_accounts_ocil:questionnaire:1">
29 ······<ocil:title>Use·Dedicated·Service·Accounts</ocil:title>29 ······<ocil:title>Use·Dedicated·Service·Accounts</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-dedicated_service_accounts_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-dedicated_service_accounts_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_conf_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title>35 ······<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policies_namespaces_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·that·application·Namespaces·have·Network·Policies·defined.</ocil:title>41 ······<ocil:title>Ensure·Private·Endpoint·Access</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-configure_network_policies_namespaces_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-registry_access_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_client_cert_rotation_ocil:questionnaire:1">
47 ······<ocil:title>Minimize·user·access·to·Amazon·ECR</ocil:title>47 ······<ocil:title>kubelet·-·Enable·Client·Certificate·Rotation</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-registry_access_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_client_cert_rotation_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-fargate_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_ocil:questionnaire:1">
53 ······<ocil:title>Consider·Fargate·for·Untrusted·Workloads</ocil:title>53 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-fargate_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_conf_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">
59 ······<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title>59 ······<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_kubelet_conf_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_defaults_ocil:questionnaire:1">
65 ······<ocil:title>Verify·Permissions·on·The·Kubelet·Configuration·File</ocil:title>65 ······<ocil:title>kubelet·-·Enable·Protect·Kernel·Defaults</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_kubelet_conf_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_protect_kernel_defaults_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-audit_logging_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>71 ······<ocil:title>Ensure·Audit·Logging·is·Enabled</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_logging_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-approved_registries_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1">
77 ······<ocil:title>Only·use·approved·container·registries</ocil:title>77 ······<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-approved_registries_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-control_plane_access_ocil:questionnaire:1"> 
83 ······<ocil:title>Restrict·Access·to·the·Control·Plane·Endpoint</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_kubelet_conf_ocil:questionnaire:1">
 83 ······<ocil:title>Verify·Permissions·on·The·Kubelet·Configuration·File</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-control_plane_access_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_kubelet_conf_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-image_scanning_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-image_scanning_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·Image·Vulnerability·Scanning</ocil:title>89 ······<ocil:title>Ensure·Image·Vulnerability·Scanning</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-image_scanning_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-image_scanning_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">
 95 ······<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title>
95 ······<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title> 
96 ······<ocil:actions> 
97 ········<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref> 
98 ······</ocil:actions> 
99 ····</ocil:questionnaire> 
100 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1"> 
101 ······<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title> 
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1"> 
107 ······<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">
 101 ······<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1"> 
113 ······<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1">
 107 ······<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_logging_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-fargate_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·Audit·Logging·is·Enabled</ocil:title>113 ······<ocil:title>Consider·Fargate·for·Untrusted·Workloads</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_logging_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-fargate_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">
Max diff block lines reached; 73274/84877 bytes (86.33%) of diff not shown.
55.7 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
55.6 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:mozilla:firefox">28 ······<cpe-dict:cpe-item·name="cpe:/a:mozilla:firefox">
29 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Firefox.·It·is·a·rendering·of40 configuration·settings·for·Firefox.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 3488, 15 lines modifiedOffset 3488, 15 lines modified
3488 ··············<xccdf-1.2:check-content-ref·href="ssg-firefox-ocil.xml"·name="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"/>3488 ··············<xccdf-1.2:check-content-ref·href="ssg-firefox-ocil.xml"·name="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"/>
3489 ············</xccdf-1.2:check>3489 ············</xccdf-1.2:check>
3490 ··········</xccdf-1.2:Rule>3490 ··········</xccdf-1.2:Rule>
3491 ········</xccdf-1.2:Group>3491 ········</xccdf-1.2:Group>
3492 ······</xccdf-1.2:Group>3492 ······</xccdf-1.2:Group>
3493 ····</xccdf-1.2:Benchmark>3493 ····</xccdf-1.2:Benchmark>
3494 ··</ds:component>3494 ··</ds:component>
3495 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-oval.xml"·timestamp="2025-02-28T20:08:00">3495 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-oval.xml"·timestamp="2025-03-01T22:08:00">
3496 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">3496 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
3497 ······<oval-def:generator>3497 ······<oval-def:generator>
3498 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>3498 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
3499 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>3499 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
3500 ········<oval:schema_version>5.11</oval:schema_version>3500 ········<oval:schema_version>5.11</oval:schema_version>
3501 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>3501 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
3502 ······</oval-def:generator>3502 ······</oval-def:generator>
Offset 5198, 515 lines modifiedOffset 5198, 459 lines modified
5198 ··············<oval-def:literal_component>/distribution</oval-def:literal_component>5198 ··············<oval-def:literal_component>/distribution</oval-def:literal_component>
5199 ············</oval-def:concat>5199 ············</oval-def:concat>
5200 ··········</oval-def:unique>5200 ··········</oval-def:unique>
5201 ········</oval-def:local_variable>5201 ········</oval-def:local_variable>
5202 ······</oval-def:variables>5202 ······</oval-def:variables>
5203 ····</oval-def:oval_definitions>5203 ····</oval-def:oval_definitions>
5204 ··</ds:component>5204 ··</ds:component>
5205 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-ocil.xml"·timestamp="2025-02-28T20:08:00">5205 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-ocil.xml"·timestamp="2025-03-01T22:08:00">
5206 ····<ocil:ocil>5206 ····<ocil:ocil>
5207 ······<ocil:generator>5207 ······<ocil:generator>
5208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>5208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>5209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
5210 ········<ocil:schema_version>2.0</ocil:schema_version>5210 ········<ocil:schema_version>2.0</ocil:schema_version>
5211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>5211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
5212 ······</ocil:generator>5212 ······</ocil:generator>
5213 ······<ocil:questionnaires>5213 ······<ocil:questionnaires>
5214 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1"> 
5215 ··········<ocil:title>Enabled·Firefox·Enhanced·Tracking·Protection</ocil:title> 
5216 ··········<ocil:actions> 
5217 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref> 
5218 ··········</ocil:actions> 
5219 ········</ocil:questionnaire> 
5220 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1"> 
5221 ··········<ocil:title>Disable·Firefox·Development·Tools</ocil:title> 
5222 ··········<ocil:actions> 
5223 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref> 
5224 ··········</ocil:actions> 
5225 ········</ocil:questionnaire> 
5226 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1"> 
5227 ··········<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title> 
5228 ··········<ocil:actions> 
5229 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref> 
5230 ··········</ocil:actions> 
5231 ········</ocil:questionnaire> 
5232 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">5214 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">
5233 ··········<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>5215 ··········<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>
5234 ··········<ocil:actions>5216 ··········<ocil:actions>
5235 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>5217 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>
5236 ··········</ocil:actions>5218 ··········</ocil:actions>
5237 ········</ocil:questionnaire>5219 ········</ocil:questionnaire>
5238 ········<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">5220 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">
5239 ··········<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>5221 ··········<ocil:title>Disable·Firefox·Telemetry</ocil:title>
5240 ··········<ocil:actions>5222 ··········<ocil:actions>
5241 ············<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>5223 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>
5242 ··········</ocil:actions>5224 ··········</ocil:actions>
5243 ········</ocil:questionnaire>5225 ········</ocil:questionnaire>
5244 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">5226 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">
5245 ··········<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>5227 ··········<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>
5246 ··········<ocil:actions>5228 ··········<ocil:actions>
5247 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>5229 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>
5248 ··········</ocil:actions>5230 ··········</ocil:actions>
5249 ········</ocil:questionnaire>5231 ········</ocil:questionnaire>
5250 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1">5232 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1">
5251 ··········<ocil:title>Enable·Shared·System·Certificates</ocil:title>5233 ··········<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title>
5252 ··········<ocil:actions>5234 ··········<ocil:actions>
5253 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>5235 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref>
5254 ··········</ocil:actions>5236 ··········</ocil:actions>
5255 ········</ocil:questionnaire>5237 ········</ocil:questionnaire>
5256 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">5238 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">
5257 ··········<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>5239 ··········<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>
5258 ··········<ocil:actions>5240 ··········<ocil:actions>
5259 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>5241 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>
5260 ··········</ocil:actions>5242 ··········</ocil:actions>
5261 ········</ocil:questionnaire>5243 ········</ocil:questionnaire>
5262 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_update_ocil:questionnaire:1">5244 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">
5263 ··········<ocil:title>Disable·Installed·Search·Plugins·Update·Checking</ocil:title>5245 ··········<ocil:title>Enable·Certificate·Verification</ocil:title>
5264 ··········<ocil:actions>5246 ··········<ocil:actions>
5265 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-search_update_action:testaction:1</ocil:test_action_ref>5247 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>
5266 ··········</ocil:actions>5248 ··········</ocil:actions>
5267 ········</ocil:questionnaire>5249 ········</ocil:questionnaire>
5268 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">5250 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">
5269 ··········<ocil:title>Disable·Firefox·Telemetry</ocil:title>5251 ··········<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>
5270 ··········<ocil:actions>5252 ··········<ocil:actions>
5271 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>5253 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>
5272 ··········</ocil:actions>5254 ··········</ocil:actions>
5273 ········</ocil:questionnaire>5255 ········</ocil:questionnaire>
5274 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">5256 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">
5275 ··········<ocil:title>Disable·Firefox·Studies</ocil:title>5257 ··········<ocil:title>Disable·Firefox·Studies</ocil:title>
5276 ··········<ocil:actions>5258 ··········<ocil:actions>
5277 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref>5259 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref>
5278 ··········</ocil:actions>5260 ··········</ocil:actions>
5279 ········</ocil:questionnaire>5261 ········</ocil:questionnaire>
5280 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">5262 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">
 5263 ··········<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>
5281 ··········<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title> 
5282 ··········<ocil:actions> 
5283 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref> 
Max diff block lines reached; 45857/56835 bytes (80.68%) of diff not shown.
48.6 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ocil.xml
48.5 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ocil.xml
Ordering differences only
    
Offset 3, 506 lines modifiedOffset 3, 450 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1"> 
11 ······<ocil:title>Enabled·Firefox·Enhanced·Tracking·Protection</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1"> 
17 ······<ocil:title>Disable·Firefox·Development·Tools</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1"> 
23 ······<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">
29 ······<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>11 ······<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>
30 ······<ocil:actions>12 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>14 ······</ocil:actions>
33 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">
35 ······<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>17 ······<ocil:title>Disable·Firefox·Telemetry</ocil:title>
36 ······<ocil:actions>18 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>20 ······</ocil:actions>
39 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">
41 ······<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>23 ······<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1">
47 ······<ocil:title>Enable·Shared·System·Certificates</ocil:title>29 ······<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">
53 ······<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>35 ······<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>
54 ······<ocil:actions>36 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>38 ······</ocil:actions>
57 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_update_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">
59 ······<ocil:title>Disable·Installed·Search·Plugins·Update·Checking</ocil:title>41 ······<ocil:title>Enable·Certificate·Verification</ocil:title>
60 ······<ocil:actions>42 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_update_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>44 ······</ocil:actions>
63 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">
65 ······<ocil:title>Disable·Firefox·Telemetry</ocil:title>47 ······<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>
66 ······<ocil:actions>48 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>50 ······</ocil:actions>
69 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">
71 ······<ocil:title>Disable·Firefox·Studies</ocil:title>53 ······<ocil:title>Disable·Firefox·Studies</ocil:title>
72 ······<ocil:actions>54 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>56 ······</ocil:actions>
75 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">
 59 ······<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>
77 ······<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title> 
78 ······<ocil:actions> 
79 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref> 
80 ······</ocil:actions> 
81 ····</ocil:questionnaire> 
82 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1"> 
83 ······<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title> 
84 ······<ocil:actions>60 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>62 ······</ocil:actions>
87 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">
89 ······<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>65 ······<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>
90 ······<ocil:actions>66 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>68 ······</ocil:actions>
93 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">
95 ······<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>71 ······<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>
96 ······<ocil:actions>72 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>74 ······</ocil:actions>
99 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">
101 ······<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title>77 ······<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>
102 ······<ocil:actions>78 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>80 ······</ocil:actions>
105 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">
107 ······<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>83 ······<ocil:title>Disable·Firefox·Development·Tools</ocil:title>
108 ······<ocil:actions>84 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>86 ······</ocil:actions>
111 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1">
113 ······<ocil:title>Disable·Firefox·Pocket</ocil:title>89 ······<ocil:title>Enable·Shared·System·Certificates</ocil:title>
114 ······<ocil:actions>90 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>92 ······</ocil:actions>
117 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">
119 ······<ocil:title>Disable·Firefox·network·prediction</ocil:title>95 ······<ocil:title>Disable·Firefox·network·prediction</ocil:title>
120 ······<ocil:actions>96 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>98 ······</ocil:actions>
123 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1">
125 ······<ocil:title>Ensure·the·Content·Blocker·uBlock·Origin·is·Installed</ocil:title>101 ······<ocil:title>Enabled·Firefox·Enhanced·Tracking·Protection</ocil:title>
126 ······<ocil:actions>102 ······<ocil:actions>
127 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-content_blocker_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref>
128 ······</ocil:actions>104 ······</ocil:actions>
Max diff block lines reached; 38359/49553 bytes (77.41%) of diff not shown.
9.94 MB
ssg-debderived_0.1.76-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0·····3044·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0·····3048·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0··3722360·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0··3722140·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
9.94 MB
data.tar.xz
9.94 MB
data.tar
698 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
698 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.xenial.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.xenial.usn.oval.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.xenial.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.xenial.usn.oval.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~">30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~">
31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·16.04·(Xenial)</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·16.04·(Xenial)</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1604:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1604:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of42 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 63230, 15 lines modifiedOffset 63230, 15 lines modified
63230 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1604-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>63230 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1604-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
63231 ············</xccdf-1.2:check>63231 ············</xccdf-1.2:check>
63232 ··········</xccdf-1.2:Rule>63232 ··········</xccdf-1.2:Rule>
63233 ········</xccdf-1.2:Group>63233 ········</xccdf-1.2:Group>
63234 ······</xccdf-1.2:Group>63234 ······</xccdf-1.2:Group>
63235 ····</xccdf-1.2:Benchmark>63235 ····</xccdf-1.2:Benchmark>
63236 ··</ds:component>63236 ··</ds:component>
63237 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"·timestamp="2025-02-28T20:08:00">63237 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"·timestamp="2025-03-01T22:08:00">
63238 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">63238 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
63239 ······<oval-def:generator>63239 ······<oval-def:generator>
63240 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>63240 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
63241 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>63241 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
63242 ········<oval:schema_version>5.11</oval:schema_version>63242 ········<oval:schema_version>5.11</oval:schema_version>
63243 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>63243 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
63244 ······</oval-def:generator>63244 ······</oval-def:generator>
Offset 79818, 7223 lines modifiedOffset 79818, 7223 lines modified
79818 ············</oval-def:arithmetic>79818 ············</oval-def:arithmetic>
79819 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>79819 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
79820 ··········</oval-def:arithmetic>79820 ··········</oval-def:arithmetic>
79821 ········</oval-def:local_variable>79821 ········</oval-def:local_variable>
79822 ······</oval-def:variables>79822 ······</oval-def:variables>
79823 ····</oval-def:oval_definitions>79823 ····</oval-def:oval_definitions>
79824 ··</ds:component>79824 ··</ds:component>
79825 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"·timestamp="2025-02-28T20:08:00">79825 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"·timestamp="2025-03-01T22:08:00">
79826 ····<ocil:ocil>79826 ····<ocil:ocil>
79827 ······<ocil:generator>79827 ······<ocil:generator>
79828 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>79828 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
79829 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>79829 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
79830 ········<ocil:schema_version>2.0</ocil:schema_version>79830 ········<ocil:schema_version>2.0</ocil:schema_version>
79831 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>79831 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
79832 ······</ocil:generator>79832 ······</ocil:generator>
79833 ······<ocil:questionnaires>79833 ······<ocil:questionnaires>
79834 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_hibernation_ocil:questionnaire:1">79834 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_gshadow_ocil:questionnaire:1">
79835 ··········<ocil:title>Disable·hibernation</ocil:title>79835 ··········<ocil:title>Verify·User·Who·Owns·gshadow·File</ocil:title>
79836 ··········<ocil:actions>79836 ··········<ocil:actions>
79837 ············<ocil:test_action_ref>ocil:ssg-kernel_config_hibernation_action:testaction:1</ocil:test_action_ref>79837 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_gshadow_action:testaction:1</ocil:test_action_ref>
79838 ··········</ocil:actions>79838 ··········</ocil:actions>
79839 ········</ocil:questionnaire>79839 ········</ocil:questionnaire>
79840 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">79840 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlinkat_ocil:questionnaire:1">
79841 ··········<ocil:title>Disable·SSH·Root·Login</ocil:title>79841 ··········<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlinkat</ocil:title>
79842 ··········<ocil:actions>79842 ··········<ocil:actions>
79843 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>79843 ············<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlinkat_action:testaction:1</ocil:test_action_ref>
79844 ··········</ocil:actions>79844 ··········</ocil:actions>
79845 ········</ocil:questionnaire>79845 ········</ocil:questionnaire>
79846 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1">79846 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1">
79847 ··········<ocil:title>Disable·the·IPv6·protocol</ocil:title>79847 ··········<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title>
79848 ··········<ocil:actions>79848 ··········<ocil:actions>
79849 ············<ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref>79849 ············<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref>
79850 ··········</ocil:actions>79850 ··········</ocil:actions>
79851 ········</ocil:questionnaire>79851 ········</ocil:questionnaire>
79852 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1">79852 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_brk_ocil:questionnaire:1">
79853 ··········<ocil:title>Specify·module·signing·key·to·use</ocil:title>79853 ··········<ocil:title>Disable·compatibility·with·brk()</ocil:title>
79854 ··········<ocil:actions>79854 ··········<ocil:actions>
79855 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>79855 ············<ocil:test_action_ref>ocil:ssg-kernel_config_compat_brk_action:testaction:1</ocil:test_action_ref>
79856 ··········</ocil:actions>79856 ··········</ocil:actions>
79857 ········</ocil:questionnaire>79857 ········</ocil:questionnaire>
79858 ········<ocil:questionnaire·id="ocil:ssg-partition_for_tmp_ocil:questionnaire:1">79858 ········<ocil:questionnaire·id="ocil:ssg-service_ip6tables_enabled_ocil:questionnaire:1">
79859 ··········<ocil:title>Ensure·/tmp·Located·On·Separate·Partition</ocil:title>79859 ··········<ocil:title>Verify·ip6tables·Enabled·if·Using·IPv6</ocil:title>
79860 ··········<ocil:actions>79860 ··········<ocil:actions>
79861 ············<ocil:test_action_ref>ocil:ssg-partition_for_tmp_action:testaction:1</ocil:test_action_ref>79861 ············<ocil:test_action_ref>ocil:ssg-service_ip6tables_enabled_action:testaction:1</ocil:test_action_ref>
79862 ··········</ocil:actions>79862 ··········</ocil:actions>
79863 ········</ocil:questionnaire>79863 ········</ocil:questionnaire>
79864 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_ocil:questionnaire:1">79864 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_adjtimex_ocil:questionnaire:1">
79865 ··········<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·for·All·IPv4·Interfaces</ocil:title>79865 ··········<ocil:title>Record·attempts·to·alter·time·through·adjtimex</ocil:title>
79866 ··········<ocil:actions>79866 ··········<ocil:actions>
79867 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_action:testaction:1</ocil:test_action_ref>79867 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_adjtimex_action:testaction:1</ocil:test_action_ref>
79868 ··········</ocil:actions>79868 ··········</ocil:actions>
79869 ········</ocil:questionnaire>79869 ········</ocil:questionnaire>
79870 ········<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1">79870 ········<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1">
79871 ··········<ocil:title>Set·Password·Minimum·Age</ocil:title>79871 ··········<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title>
79872 ··········<ocil:actions>79872 ··········<ocil:actions>
79873 ············<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref>79873 ············<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref>
79874 ··········</ocil:actions>79874 ··········</ocil:actions>
79875 ········</ocil:questionnaire>79875 ········</ocil:questionnaire>
79876 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1">79876 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_shadow_ocil:questionnaire:1">
79877 ··········<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title>79877 ··········<ocil:title>Verify·Group·Who·Owns·shadow·File</ocil:title>
79878 ··········<ocil:actions>79878 ··········<ocil:actions>
79879 ············<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>79879 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_shadow_action:testaction:1</ocil:test_action_ref>
79880 ··········</ocil:actions>79880 ··········</ocil:actions>
79881 ········</ocil:questionnaire>79881 ········</ocil:questionnaire>
79882 ········<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">79882 ········<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_forward_ocil:questionnaire:1">
79883 ··········<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title>79883 ··········<ocil:title>Set·Default·iptables·Policy·for·Forwarded·Packets</ocil:title>
79884 ··········<ocil:actions>79884 ··········<ocil:actions>
79885 ············<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref>79885 ············<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_forward_action:testaction:1</ocil:test_action_ref>
79886 ··········</ocil:actions>79886 ··········</ocil:actions>
79887 ········</ocil:questionnaire>79887 ········</ocil:questionnaire>
79888 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1"> 
79889 ··········<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rename</ocil:title>79888 ········<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">
 79889 ··········<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>
79890 ··········<ocil:actions>79890 ··········<ocil:actions>
79891 ············<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1</ocil:test_action_ref>79891 ············<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>
79892 ··········</ocil:actions>79892 ··········</ocil:actions>
79893 ········</ocil:questionnaire>79893 ········</ocil:questionnaire>
79894 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">79894 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_no_sanity_ocil:questionnaire:1">
79895 ··········<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>79895 ··········<ocil:title>Enable·poison·without·sanity·check</ocil:title>
79896 ··········<ocil:actions>79896 ··········<ocil:actions>
79897 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>79897 ············<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_no_sanity_action:testaction:1</ocil:test_action_ref>
79898 ··········</ocil:actions>79898 ··········</ocil:actions>
79899 ········</ocil:questionnaire>79899 ········</ocil:questionnaire>
79900 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> 
79901 ··········<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>79900 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1">
 79901 ··········<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title>
79902 ··········<ocil:actions>79902 ··········<ocil:actions>
Max diff block lines reached; 702164/714566 bytes (98.26%) of diff not shown.
664 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ocil.xml
664 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ocil.xml
Ordering differences only
    
Offset 3, 7205 lines modifiedOffset 3, 7205 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_hibernation_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_gshadow_ocil:questionnaire:1">
11 ······<ocil:title>Disable·hibernation</ocil:title>11 ······<ocil:title>Verify·User·Who·Owns·gshadow·File</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_hibernation_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_gshadow_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlinkat_ocil:questionnaire:1">
17 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>17 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlinkat</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlinkat_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1">
23 ······<ocil:title>Disable·the·IPv6·protocol</ocil:title>23 ······<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_brk_ocil:questionnaire:1">
29 ······<ocil:title>Specify·module·signing·key·to·use</ocil:title>29 ······<ocil:title>Disable·compatibility·with·brk()</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_compat_brk_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-partition_for_tmp_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-service_ip6tables_enabled_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·/tmp·Located·On·Separate·Partition</ocil:title>35 ······<ocil:title>Verify·ip6tables·Enabled·if·Using·IPv6</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-partition_for_tmp_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-service_ip6tables_enabled_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_ocil:questionnaire:1"> 
41 ······<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·for·All·IPv4·Interfaces</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_adjtimex_ocil:questionnaire:1">
 41 ······<ocil:title>Record·attempts·to·alter·time·through·adjtimex</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_adjtimex_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1">
47 ······<ocil:title>Set·Password·Minimum·Age</ocil:title>47 ······<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_shadow_ocil:questionnaire:1">
53 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title>53 ······<ocil:title>Verify·Group·Who·Owns·shadow·File</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_shadow_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_forward_ocil:questionnaire:1">
59 ······<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title>59 ······<ocil:title>Set·Default·iptables·Policy·for·Forwarded·Packets</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_forward_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1"> 
65 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rename</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">
 65 ······<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_no_sanity_ocil:questionnaire:1">
71 ······<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>71 ······<ocil:title>Enable·poison·without·sanity·check</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_no_sanity_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> 
77 ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1">
 77 ······<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
83 ······<ocil:title>Enable·checks·on·scatter-gather·(SG)·table·operations</ocil:title>83 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_sg_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">
89 ······<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>89 ······<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1">
95 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>95 ······<ocil:title>Limit·the·Number·of·Concurrent·Login·Sessions·Allowed·Per·User</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-service_ufw_enabled_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nosuid_ocil:questionnaire:1">
101 ······<ocil:title>Verify·ufw·Enabled</ocil:title>101 ······<ocil:title>Add·nosuid·Option·to·/dev/shm</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-service_ufw_enabled_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nosuid_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1">
107 ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls</ocil:title>107 ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Root</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_ownership_audit_configuration_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">
113 ······<ocil:title>IOMMU·configuration·directive</ocil:title>113 ······<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-grub2_enable_iommu_force_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-package_nss-tools_installed_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·nss-tools·is·installed</ocil:title>119 ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-package_nss-tools_installed_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_binary_dirs_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">
125 ······<ocil:title>Verify·that·System·Executable·Directories·Have·Restrictive·Permissions</ocil:title>125 ······<ocil:title>The·Chrony·package·is·installed</ocil:title>
126 ······<ocil:actions>126 ······<ocil:actions>
Max diff block lines reached; 666989/679695 bytes (98.13%) of diff not shown.
725 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
725 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.bionic.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.bionic.usn.oval.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.bionic.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.bionic.usn.oval.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~">30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~">
31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·18.04·(Bionic·Beaver)</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·18.04·(Bionic·Beaver)</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1804:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1804:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of42 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 67111, 15 lines modifiedOffset 67111, 15 lines modified
67111 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1804-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>67111 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1804-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
67112 ············</xccdf-1.2:check>67112 ············</xccdf-1.2:check>
67113 ··········</xccdf-1.2:Rule>67113 ··········</xccdf-1.2:Rule>
67114 ········</xccdf-1.2:Group>67114 ········</xccdf-1.2:Group>
67115 ······</xccdf-1.2:Group>67115 ······</xccdf-1.2:Group>
67116 ····</xccdf-1.2:Benchmark>67116 ····</xccdf-1.2:Benchmark>
67117 ··</ds:component>67117 ··</ds:component>
67118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"·timestamp="2025-02-28T20:08:00">67118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"·timestamp="2025-03-01T22:08:00">
67119 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">67119 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
67120 ······<oval-def:generator>67120 ······<oval-def:generator>
67121 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>67121 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
67122 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>67122 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
67123 ········<oval:schema_version>5.11</oval:schema_version>67123 ········<oval:schema_version>5.11</oval:schema_version>
67124 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>67124 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
67125 ······</oval-def:generator>67125 ······</oval-def:generator>
Offset 84657, 3998 lines modifiedOffset 84657, 3998 lines modified
84657 ············</oval-def:arithmetic>84657 ············</oval-def:arithmetic>
84658 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>84658 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
84659 ··········</oval-def:arithmetic>84659 ··········</oval-def:arithmetic>
84660 ········</oval-def:local_variable>84660 ········</oval-def:local_variable>
84661 ······</oval-def:variables>84661 ······</oval-def:variables>
84662 ····</oval-def:oval_definitions>84662 ····</oval-def:oval_definitions>
84663 ··</ds:component>84663 ··</ds:component>
84664 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"·timestamp="2025-02-28T20:08:00">84664 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"·timestamp="2025-03-01T22:08:00">
84665 ····<ocil:ocil>84665 ····<ocil:ocil>
84666 ······<ocil:generator>84666 ······<ocil:generator>
84667 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>84667 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
84668 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>84668 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
84669 ········<ocil:schema_version>2.0</ocil:schema_version>84669 ········<ocil:schema_version>2.0</ocil:schema_version>
84670 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>84670 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
84671 ······</ocil:generator>84671 ······</ocil:generator>
84672 ······<ocil:questionnaires>84672 ······<ocil:questionnaires>
84673 ········<ocil:questionnaire·id="ocil:ssg-auditd_log_format_ocil:questionnaire:1">84673 ········<ocil:questionnaire·id="ocil:ssg-package_audit_installed_ocil:questionnaire:1">
84674 ··········<ocil:title>Resolve·information·before·writing·to·audit·logs</ocil:title>84674 ··········<ocil:title>Ensure·the·audit·Subsystem·is·Installed</ocil:title>
84675 ··········<ocil:actions>84675 ··········<ocil:actions>
84676 ············<ocil:test_action_ref>ocil:ssg-auditd_log_format_action:testaction:1</ocil:test_action_ref>84676 ············<ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>
84677 ··········</ocil:actions>84677 ··········</ocil:actions>
84678 ········</ocil:questionnaire>84678 ········</ocil:questionnaire>
84679 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1">84679 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">
84680 ··········<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title>84680 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>
84681 ··········<ocil:actions>84681 ··········<ocil:actions>
84682 ············<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref>84682 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>
84683 ··········</ocil:actions>84683 ··········</ocil:actions>
84684 ········</ocil:questionnaire>84684 ········</ocil:questionnaire>
84685 ········<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">84685 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_all_shadowed_ocil:questionnaire:1">
84686 ··········<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>84686 ··········<ocil:title>Verify·All·Account·Password·Hashes·are·Shadowed</ocil:title>
84687 ··········<ocil:actions>84687 ··········<ocil:actions>
84688 ············<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>84688 ············<ocil:test_action_ref>ocil:ssg-accounts_password_all_shadowed_action:testaction:1</ocil:test_action_ref>
84689 ··········</ocil:actions>84689 ··········</ocil:actions>
84690 ········</ocil:questionnaire>84690 ········</ocil:questionnaire>
84691 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1">84691 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_vdso_ocil:questionnaire:1">
84692 ··········<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>84692 ··········<ocil:title>Disable·the·32-bit·vDSO</ocil:title>
84693 ··········<ocil:actions>84693 ··········<ocil:actions>
84694 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>84694 ············<ocil:test_action_ref>ocil:ssg-kernel_config_compat_vdso_action:testaction:1</ocil:test_action_ref>
84695 ··········</ocil:actions>84695 ··········</ocil:actions>
84696 ········</ocil:questionnaire>84696 ········</ocil:questionnaire>
84697 ········<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1">84697 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">
84698 ··········<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title>84698 ··········<ocil:title>Verify·User·Who·Owns·Backup·gshadow·File</ocil:title>
84699 ··········<ocil:actions>84699 ··········<ocil:actions>
84700 ············<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>84700 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
84701 ··········</ocil:actions>84701 ··········</ocil:actions>
84702 ········</ocil:questionnaire>84702 ········</ocil:questionnaire>
84703 ········<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_etc_shadow_ocil:questionnaire:1">84703 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">
84704 ··········<ocil:title>Ensure·There·Are·No·Accounts·With·Blank·or·Null·Passwords</ocil:title>84704 ··········<ocil:title>Disable·SSH·Root·Login</ocil:title>
84705 ··········<ocil:actions>84705 ··········<ocil:actions>
84706 ············<ocil:test_action_ref>ocil:ssg-no_empty_passwords_etc_shadow_action:testaction:1</ocil:test_action_ref>84706 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>
84707 ··········</ocil:actions>84707 ··········</ocil:actions>
84708 ········</ocil:questionnaire>84708 ········</ocil:questionnaire>
84709 ········<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">84709 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">
84710 ··········<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title>84710 ··········<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>
84711 ··········<ocil:actions>84711 ··········<ocil:actions>
84712 ············<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref>84712 ············<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>
84713 ··········</ocil:actions>84713 ··········</ocil:actions>
84714 ········</ocil:questionnaire>84714 ········</ocil:questionnaire>
84715 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">84715 ········<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1">
84716 ··········<ocil:title>Disable·TIPC·Support</ocil:title>84716 ··········<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title>
84717 ··········<ocil:actions>84717 ··········<ocil:actions>
84718 ············<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>84718 ············<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>
84719 ··········</ocil:actions>84719 ··········</ocil:actions>
84720 ········</ocil:questionnaire>84720 ········</ocil:questionnaire>
84721 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_all_shadowed_ocil:questionnaire:1">84721 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1">
84722 ··········<ocil:title>Verify·All·Account·Password·Hashes·are·Shadowed</ocil:title>84722 ··········<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title>
84723 ··········<ocil:actions>84723 ··········<ocil:actions>
84724 ············<ocil:test_action_ref>ocil:ssg-accounts_password_all_shadowed_action:testaction:1</ocil:test_action_ref>84724 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
84725 ··········</ocil:actions>84725 ··········</ocil:actions>
84726 ········</ocil:questionnaire>84726 ········</ocil:questionnaire>
84727 ········<ocil:questionnaire·id="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1">84727 ········<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">
84728 ··········<ocil:title>Ensure·SELinux·is·Not·Disabled</ocil:title>84728 ··········<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>
84729 ··········<ocil:actions>84729 ··········<ocil:actions>
84730 ············<ocil:test_action_ref>ocil:ssg-selinux_not_disabled_action:testaction:1</ocil:test_action_ref>84730 ············<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>
84731 ··········</ocil:actions>84731 ··········</ocil:actions>
84732 ········</ocil:questionnaire>84732 ········</ocil:questionnaire>
84733 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_filter_ocil:questionnaire:1">84733 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_ocil:questionnaire:1">
84734 ··········<ocil:title>Enable·use·of·Berkeley·Packet·Filter·with·seccomp</ocil:title>84734 ··········<ocil:title>Verify·Permissions·on·/var/log·Directory</ocil:title>
84735 ··········<ocil:actions>84735 ··········<ocil:actions>
84736 ············<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_filter_action:testaction:1</ocil:test_action_ref>84736 ············<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_action:testaction:1</ocil:test_action_ref>
84737 ··········</ocil:actions>84737 ··········</ocil:actions>
84738 ········</ocil:questionnaire>84738 ········</ocil:questionnaire>
84739 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">84739 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">
84740 ··········<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>84740 ··········<ocil:title>Enable·module·signature·verification</ocil:title>
84741 ··········<ocil:actions>84741 ··········<ocil:actions>
84742 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>84742 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>
84743 ··········</ocil:actions>84743 ··········</ocil:actions>
Max diff block lines reached; 730100/742458 bytes (98.34%) of diff not shown.
690 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ocil.xml
690 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ocil.xml
Ordering differences only
    
Offset 3, 3989 lines modifiedOffset 3, 3989 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-auditd_log_format_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-package_audit_installed_ocil:questionnaire:1">
11 ······<ocil:title>Resolve·information·before·writing·to·audit·logs</ocil:title>11 ······<ocil:title>Ensure·the·audit·Subsystem·is·Installed</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-auditd_log_format_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">
17 ······<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title>17 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_all_shadowed_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>23 ······<ocil:title>Verify·All·Account·Password·Hashes·are·Shadowed</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-accounts_password_all_shadowed_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_vdso_ocil:questionnaire:1">
29 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>29 ······<ocil:title>Disable·the·32-bit·vDSO</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_compat_vdso_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title>35 ······<ocil:title>Verify·User·Who·Owns·Backup·gshadow·File</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_etc_shadow_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·There·Are·No·Accounts·With·Blank·or·Null·Passwords</ocil:title>41 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-no_empty_passwords_etc_shadow_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">
47 ······<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title>47 ······<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1">
53 ······<ocil:title>Disable·TIPC·Support</ocil:title>53 ······<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_all_shadowed_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1">
59 ······<ocil:title>Verify·All·Account·Password·Hashes·are·Shadowed</ocil:title>59 ······<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-accounts_password_all_shadowed_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·SELinux·is·Not·Disabled</ocil:title>65 ······<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-selinux_not_disabled_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_filter_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_ocil:questionnaire:1">
71 ······<ocil:title>Enable·use·of·Berkeley·Packet·Filter·with·seccomp</ocil:title>71 ······<ocil:title>Verify·Permissions·on·/var/log·Directory</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_filter_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">
77 ······<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>77 ······<ocil:title>Enable·module·signature·verification</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1">
83 ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>83 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1"> 
89 ······<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_audit_ocil:questionnaire:1">
 89 ······<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·SMAP·is·not·disabled·during·boot</ocil:title>95 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1"> 
101 ······<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1">
 101 ······<ocil:title>Ensure·SELinux·is·Not·Disabled</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-selinux_not_disabled_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-aide_disable_silentreports_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_force_ocil:questionnaire:1">
107 ······<ocil:title>Configure·AIDE·To·Notify·Personnel·if·Baseline·Configurations·Are·Altered</ocil:title>107 ······<ocil:title>Require·modules·to·be·validly·signed</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-aide_disable_silentreports_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_force_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-mount_option_noexec_removable_partitions_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_notifiers_ocil:questionnaire:1">
113 ······<ocil:title>Add·noexec·Option·to·Removable·Media·Partitions</ocil:title>113 ······<ocil:title>Enable·checks·on·notifier·call·chains</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-mount_option_noexec_removable_partitions_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_notifiers_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1"> 
119 ······<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_ocil:questionnaire:1">
 119 ······<ocil:title>Prevent·Login·to·Accounts·With·Empty·Password</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-no_empty_passwords_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_systemmap_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1">
125 ······<ocil:title>Verify·Permissions·on·System.map·Files</ocil:title>125 ······<ocil:title>Configure·Polyinstantiation·of·/var/tmp·Directories</ocil:title>
126 ······<ocil:actions>126 ······<ocil:actions>
Max diff block lines reached; 693550/706326 bytes (98.19%) of diff not shown.
1.37 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
1.37 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~">28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~">
29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·20.04·(Focal·Fossa)</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·20.04·(Focal·Fossa)</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2004:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2004:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of40 configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 143123, 15 lines modifiedOffset 143123, 15 lines modified
143123 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2004-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>143123 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2004-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>
143124 ············</xccdf-1.2:check>143124 ············</xccdf-1.2:check>
143125 ··········</xccdf-1.2:Rule>143125 ··········</xccdf-1.2:Rule>
143126 ········</xccdf-1.2:Group>143126 ········</xccdf-1.2:Group>
143127 ······</xccdf-1.2:Group>143127 ······</xccdf-1.2:Group>
143128 ····</xccdf-1.2:Benchmark>143128 ····</xccdf-1.2:Benchmark>
143129 ··</ds:component>143129 ··</ds:component>
143130 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"·timestamp="2025-02-28T20:08:00">143130 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"·timestamp="2025-03-01T22:08:00">
143131 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">143131 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
143132 ······<oval-def:generator>143132 ······<oval-def:generator>
143133 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>143133 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
143134 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>143134 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
143135 ········<oval:schema_version>5.11</oval:schema_version>143135 ········<oval:schema_version>5.11</oval:schema_version>
143136 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>143136 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
143137 ······</oval-def:generator>143137 ······</oval-def:generator>
Offset 174684, 9147 lines modifiedOffset 174684, 9012 lines modified
174684 ············</oval-def:arithmetic>174684 ············</oval-def:arithmetic>
174685 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>174685 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
174686 ··········</oval-def:arithmetic>174686 ··········</oval-def:arithmetic>
174687 ········</oval-def:local_variable>174687 ········</oval-def:local_variable>
174688 ······</oval-def:variables>174688 ······</oval-def:variables>
174689 ····</oval-def:oval_definitions>174689 ····</oval-def:oval_definitions>
174690 ··</ds:component>174690 ··</ds:component>
174691 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"·timestamp="2025-02-28T20:08:00">174691 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"·timestamp="2025-03-01T22:08:00">
174692 ····<ocil:ocil>174692 ····<ocil:ocil>
174693 ······<ocil:generator>174693 ······<ocil:generator>
174694 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>174694 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
174695 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>174695 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
174696 ········<ocil:schema_version>2.0</ocil:schema_version>174696 ········<ocil:schema_version>2.0</ocil:schema_version>
174697 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>174697 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
174698 ······</ocil:generator>174698 ······</ocil:generator>
174699 ······<ocil:questionnaires>174699 ······<ocil:questionnaires>
174700 ········<ocil:questionnaire·id="ocil:ssg-file_owner_grub2_cfg_ocil:questionnaire:1"> 
174701 ··········<ocil:title>Verify·/boot/grub/grub.cfg·User·Ownership</ocil:title> 
174702 ··········<ocil:actions> 
174703 ············<ocil:test_action_ref>ocil:ssg-file_owner_grub2_cfg_action:testaction:1</ocil:test_action_ref> 
174704 ··········</ocil:actions> 
174705 ········</ocil:questionnaire> 
174706 ········<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">174700 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_sctp_disabled_ocil:questionnaire:1">
174707 ··········<ocil:title>Install·the·cron·service</ocil:title>174701 ··········<ocil:title>Disable·SCTP·Support</ocil:title>
174708 ··········<ocil:actions>174702 ··········<ocil:actions>
174709 ············<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>174703 ············<ocil:test_action_ref>ocil:ssg-kernel_module_sctp_disabled_action:testaction:1</ocil:test_action_ref>
174710 ··········</ocil:actions>174704 ··········</ocil:actions>
174711 ········</ocil:questionnaire>174705 ········</ocil:questionnaire>
174712 ········<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1">174706 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_legacy_ptys_ocil:questionnaire:1">
174713 ··········<ocil:title>Uninstall·rsh-server·Package</ocil:title>174707 ··········<ocil:title>Disable·legacy·(BSD)·PTY·support</ocil:title>
174714 ··········<ocil:actions>174708 ··········<ocil:actions>
174715 ············<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref>174709 ············<ocil:test_action_ref>ocil:ssg-kernel_config_legacy_ptys_action:testaction:1</ocil:test_action_ref>
174716 ··········</ocil:actions>174710 ··········</ocil:actions>
174717 ········</ocil:questionnaire>174711 ········</ocil:questionnaire>
174718 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1">174712 ········<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">
174719 ··········<ocil:title>Disable·IPv6·Networking·Support·Automatic·Loading</ocil:title>174713 ··········<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>
174720 ··········<ocil:actions>174714 ··········<ocil:actions>
174721 ············<ocil:test_action_ref>ocil:ssg-kernel_module_ipv6_option_disabled_action:testaction:1</ocil:test_action_ref>174715 ············<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>
174722 ··········</ocil:actions>174716 ··········</ocil:actions>
174723 ········</ocil:questionnaire>174717 ········</ocil:questionnaire>
174724 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1">174718 ········<ocil:questionnaire·id="ocil:ssg-sudo_remove_nopasswd_ocil:questionnaire:1">
174725 ··········<ocil:title>Disable·Kerberos·Authentication</ocil:title>174719 ··········<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·NOPASSWD</ocil:title>
174726 ··········<ocil:actions>174720 ··········<ocil:actions>
174727 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref>174721 ············<ocil:test_action_ref>ocil:ssg-sudo_remove_nopasswd_action:testaction:1</ocil:test_action_ref>
174728 ··········</ocil:actions>174722 ··········</ocil:actions>
174729 ········</ocil:questionnaire>174723 ········</ocil:questionnaire>
174730 ········<ocil:questionnaire·id="ocil:ssg-grub2_systemd_debug-shell_argument_absent_ocil:questionnaire:1"> 
174731 ··········<ocil:title>Ensure·debug-shell·service·is·not·enabled·during·boot</ocil:title>174724 ········<ocil:questionnaire·id="ocil:ssg-aide_disable_silentreports_ocil:questionnaire:1">
 174725 ··········<ocil:title>Configure·AIDE·To·Notify·Personnel·if·Baseline·Configurations·Are·Altered</ocil:title>
174732 ··········<ocil:actions>174726 ··········<ocil:actions>
174733 ············<ocil:test_action_ref>ocil:ssg-grub2_systemd_debug-shell_argument_absent_action:testaction:1</ocil:test_action_ref>174727 ············<ocil:test_action_ref>ocil:ssg-aide_disable_silentreports_action:testaction:1</ocil:test_action_ref>
174734 ··········</ocil:actions>174728 ··········</ocil:actions>
174735 ········</ocil:questionnaire>174729 ········</ocil:questionnaire>
174736 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_force_ocil:questionnaire:1">174730 ········<ocil:questionnaire·id="ocil:ssg-sudoers_no_command_negation_ocil:questionnaire:1">
174737 ··········<ocil:title>Require·modules·to·be·validly·signed</ocil:title>174731 ··········<ocil:title>Don't·define·allowed·commands·in·sudoers·by·means·of·exclusion</ocil:title>
174738 ··········<ocil:actions>174732 ··········<ocil:actions>
174739 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_force_action:testaction:1</ocil:test_action_ref>174733 ············<ocil:test_action_ref>ocil:ssg-sudoers_no_command_negation_action:testaction:1</ocil:test_action_ref>
174740 ··········</ocil:actions>174734 ··········</ocil:actions>
174741 ········</ocil:questionnaire>174735 ········</ocil:questionnaire>
174742 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_private_key_ocil:questionnaire:1">174736 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_at_ocil:questionnaire:1">
174743 ··········<ocil:title>Verify·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>174737 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·at</ocil:title>
174744 ··········<ocil:actions>174738 ··········<ocil:actions>
174745 ············<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>174739 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_at_action:testaction:1</ocil:test_action_ref>
174746 ··········</ocil:actions>174740 ··········</ocil:actions>
174747 ········</ocil:questionnaire>174741 ········</ocil:questionnaire>
174748 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1">174742 ········<ocil:questionnaire·id="ocil:ssg-package_iptables_installed_ocil:questionnaire:1">
174749 ··········<ocil:title>Configure·ARP·filtering·for·All·IPv4·Interfaces</ocil:title>174743 ··········<ocil:title>Install·iptables·Package</ocil:title>
174750 ··········<ocil:actions>174744 ··········<ocil:actions>
174751 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1</ocil:test_action_ref>174745 ············<ocil:test_action_ref>ocil:ssg-package_iptables_installed_action:testaction:1</ocil:test_action_ref>
174752 ··········</ocil:actions>174746 ··········</ocil:actions>
174753 ········</ocil:questionnaire>174747 ········</ocil:questionnaire>
174754 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_crontab_ocil:questionnaire:1">174748 ········<ocil:questionnaire·id="ocil:ssg-package_ntp_installed_ocil:questionnaire:1">
174755 ··········<ocil:title>Verify·Group·Who·Owns·Crontab</ocil:title>174749 ··········<ocil:title>Install·the·ntp·service</ocil:title>
174756 ··········<ocil:actions>174750 ··········<ocil:actions>
174757 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_crontab_action:testaction:1</ocil:test_action_ref>174751 ············<ocil:test_action_ref>ocil:ssg-package_ntp_installed_action:testaction:1</ocil:test_action_ref>
174758 ··········</ocil:actions>174752 ··········</ocil:actions>
174759 ········</ocil:questionnaire>174753 ········</ocil:questionnaire>
174760 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_group_ocil:questionnaire:1">174754 ········<ocil:questionnaire·id="ocil:ssg-permissions_local_var_log_ocil:questionnaire:1">
174761 ··········<ocil:title>Verify·User·Who·Owns·Backup·group·File</ocil:title>174755 ··········<ocil:title>Verify·permissions·of·log·files</ocil:title>
174762 ··········<ocil:actions>174756 ··········<ocil:actions>
174763 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_group_action:testaction:1</ocil:test_action_ref>174757 ············<ocil:test_action_ref>ocil:ssg-permissions_local_var_log_action:testaction:1</ocil:test_action_ref>
174764 ··········</ocil:actions>174758 ··········</ocil:actions>
174765 ········</ocil:questionnaire>174759 ········</ocil:questionnaire>
174766 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1">174760 ········<ocil:questionnaire·id="ocil:ssg-grub2_mce_argument_ocil:questionnaire:1">
174767 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>174761 ··········<ocil:title>Force·kernel·panic·on·uncorrected·MCEs</ocil:title>
174768 ··········<ocil:actions>174762 ··········<ocil:actions>
174769 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>174763 ············<ocil:test_action_ref>ocil:ssg-grub2_mce_argument_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1422261/1434317 bytes (99.16%) of diff not shown.
1.31 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ocil.xml
1.31 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ocil.xml
Ordering differences only
    
Offset 3, 9138 lines modifiedOffset 3, 9003 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_grub2_cfg_ocil:questionnaire:1"> 
11 ······<ocil:title>Verify·/boot/grub/grub.cfg·User·Ownership</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-file_owner_grub2_cfg_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_sctp_disabled_ocil:questionnaire:1">
17 ······<ocil:title>Install·the·cron·service</ocil:title>11 ······<ocil:title>Disable·SCTP·Support</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-kernel_module_sctp_disabled_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1"> 
23 ······<ocil:title>Uninstall·rsh-server·Package</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_legacy_ptys_ocil:questionnaire:1">
 17 ······<ocil:title>Disable·legacy·(BSD)·PTY·support</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_legacy_ptys_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1"> 
29 ······<ocil:title>Disable·IPv6·Networking·Support·Automatic·Loading</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">
 23 ······<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_module_ipv6_option_disabled_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_nopasswd_ocil:questionnaire:1">
35 ······<ocil:title>Disable·Kerberos·Authentication</ocil:title>29 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·NOPASSWD</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_nopasswd_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-grub2_systemd_debug-shell_argument_absent_ocil:questionnaire:1"> 
41 ······<ocil:title>Ensure·debug-shell·service·is·not·enabled·during·boot</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-aide_disable_silentreports_ocil:questionnaire:1">
 35 ······<ocil:title>Configure·AIDE·To·Notify·Personnel·if·Baseline·Configurations·Are·Altered</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-grub2_systemd_debug-shell_argument_absent_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-aide_disable_silentreports_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_force_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_command_negation_ocil:questionnaire:1">
47 ······<ocil:title>Require·modules·to·be·validly·signed</ocil:title>41 ······<ocil:title>Don't·define·allowed·commands·in·sudoers·by·means·of·exclusion</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_force_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_command_negation_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_private_key_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_at_ocil:questionnaire:1">
53 ······<ocil:title>Verify·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>47 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·at</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_at_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-package_iptables_installed_ocil:questionnaire:1">
59 ······<ocil:title>Configure·ARP·filtering·for·All·IPv4·Interfaces</ocil:title>53 ······<ocil:title>Install·iptables·Package</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-package_iptables_installed_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_crontab_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-package_ntp_installed_ocil:questionnaire:1">
65 ······<ocil:title>Verify·Group·Who·Owns·Crontab</ocil:title>59 ······<ocil:title>Install·the·ntp·service</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_crontab_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-package_ntp_installed_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_group_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-permissions_local_var_log_ocil:questionnaire:1">
71 ······<ocil:title>Verify·User·Who·Owns·Backup·group·File</ocil:title>65 ······<ocil:title>Verify·permissions·of·log·files</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_group_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-permissions_local_var_log_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
77 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-grub2_mce_argument_ocil:questionnaire:1">
 71 ······<ocil:title>Force·kernel·panic·on·uncorrected·MCEs</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-grub2_mce_argument_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1">
83 ······<ocil:title>Disable·the·IPv6·protocol</ocil:title>77 ······<ocil:title>Disable·the·IPv6·protocol</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1"> 
89 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title> 
90 ······<ocil:actions> 
91 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref> 
92 ······</ocil:actions> 
93 ····</ocil:questionnaire> 
94 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1">
95 ······<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title>83 ······<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1"> 
101 ······<ocil:title>Verify·Permissions·on·crontab</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-package_nss-tools_installed_ocil:questionnaire:1">
 89 ······<ocil:title>Ensure·nss-tools·is·installed</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-package_nss-tools_installed_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-service_chronyd_enabled_ocil:questionnaire:1"> 
107 ······<ocil:title>The·Chronyd·service·is·enabled</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1">
 95 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-service_chronyd_enabled_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-package_telnet_removed_ocil:questionnaire:1"> 
113 ······<ocil:title>Remove·telnet·Clients</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1">
 101 ······<ocil:title>Disable·Accepting·Router·Advertisements·on·all·IPv6·Interfaces·by·Default</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-package_telnet_removed_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_umount_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·umount</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">
 107 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_umount_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1359739/1371157 bytes (99.17%) of diff not shown.
1.43 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
1.42 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~">28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~">
29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·22.04·(Jammy·Jellyfish)</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·22.04·(Jammy·Jellyfish)</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2204:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2204:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of40 configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 148842, 15 lines modifiedOffset 148842, 15 lines modified
148842 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2204-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>148842 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2204-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>
148843 ············</xccdf-1.2:check>148843 ············</xccdf-1.2:check>
148844 ··········</xccdf-1.2:Rule>148844 ··········</xccdf-1.2:Rule>
148845 ········</xccdf-1.2:Group>148845 ········</xccdf-1.2:Group>
148846 ······</xccdf-1.2:Group>148846 ······</xccdf-1.2:Group>
148847 ····</xccdf-1.2:Benchmark>148847 ····</xccdf-1.2:Benchmark>
148848 ··</ds:component>148848 ··</ds:component>
148849 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"·timestamp="2025-02-28T20:08:00">148849 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"·timestamp="2025-03-01T22:08:00">
148850 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">148850 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
148851 ······<oval-def:generator>148851 ······<oval-def:generator>
148852 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>148852 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
148853 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>148853 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
148854 ········<oval:schema_version>5.11</oval:schema_version>148854 ········<oval:schema_version>5.11</oval:schema_version>
148855 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>148855 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
148856 ······</oval-def:generator>148856 ······</oval-def:generator>
Offset 181748, 10623 lines modifiedOffset 181748, 10161 lines modified
181748 ············</oval-def:arithmetic>181748 ············</oval-def:arithmetic>
181749 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>181749 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
181750 ··········</oval-def:arithmetic>181750 ··········</oval-def:arithmetic>
181751 ········</oval-def:local_variable>181751 ········</oval-def:local_variable>
181752 ······</oval-def:variables>181752 ······</oval-def:variables>
181753 ····</oval-def:oval_definitions>181753 ····</oval-def:oval_definitions>
181754 ··</ds:component>181754 ··</ds:component>
181755 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"·timestamp="2025-02-28T20:08:00">181755 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"·timestamp="2025-03-01T22:08:00">
181756 ····<ocil:ocil>181756 ····<ocil:ocil>
181757 ······<ocil:generator>181757 ······<ocil:generator>
181758 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>181758 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
181759 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>181759 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
181760 ········<ocil:schema_version>2.0</ocil:schema_version>181760 ········<ocil:schema_version>2.0</ocil:schema_version>
181761 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>181761 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
181762 ······</ocil:generator>181762 ······</ocil:generator>
181763 ······<ocil:questionnaires>181763 ······<ocil:questionnaires>
181764 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1"> 
181765 ··········<ocil:title>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</ocil:title>181764 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_notifiers_ocil:questionnaire:1">
 181765 ··········<ocil:title>Enable·checks·on·notifier·call·chains</ocil:title>
181766 ··········<ocil:actions>181766 ··········<ocil:actions>
181767 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1</ocil:test_action_ref>181767 ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_notifiers_action:testaction:1</ocil:test_action_ref>
181768 ··········</ocil:actions>181768 ··········</ocil:actions>
181769 ········</ocil:questionnaire>181769 ········</ocil:questionnaire>
181770 ········<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_audit_ocil:questionnaire:1">181770 ········<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1">
181771 ··········<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>181771 ··········<ocil:title>Ensure·rsyslog·is·Installed</ocil:title>
181772 ··········<ocil:actions>181772 ··········<ocil:actions>
181773 ············<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>181773 ············<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>
181774 ··········</ocil:actions>181774 ··········</ocil:actions>
181775 ········</ocil:questionnaire>181775 ········</ocil:questionnaire>
181776 ········<ocil:questionnaire·id="ocil:ssg-auditd_write_logs_ocil:questionnaire:1">181776 ········<ocil:questionnaire·id="ocil:ssg-file_owner_sshd_config_ocil:questionnaire:1">
181777 ··········<ocil:title>Write·Audit·Logs·to·the·Disk</ocil:title>181777 ··········<ocil:title>Verify·Owner·on·SSH·Server·config·file</ocil:title>
181778 ··········<ocil:actions>181778 ··········<ocil:actions>
181779 ············<ocil:test_action_ref>ocil:ssg-auditd_write_logs_action:testaction:1</ocil:test_action_ref>181779 ············<ocil:test_action_ref>ocil:ssg-file_owner_sshd_config_action:testaction:1</ocil:test_action_ref>
181780 ··········</ocil:actions>181780 ··········</ocil:actions>
181781 ········</ocil:questionnaire>181781 ········</ocil:questionnaire>
181782 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_legacy_ptys_ocil:questionnaire:1">181782 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1">
181783 ··········<ocil:title>Disable·legacy·(BSD)·PTY·support</ocil:title>181783 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·openat</ocil:title>
181784 ··········<ocil:actions>181784 ··········<ocil:actions>
181785 ············<ocil:test_action_ref>ocil:ssg-kernel_config_legacy_ptys_action:testaction:1</ocil:test_action_ref>181785 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1</ocil:test_action_ref>
181786 ··········</ocil:actions>181786 ··········</ocil:actions>
181787 ········</ocil:questionnaire>181787 ········</ocil:questionnaire>
181788 ········<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_macs_ordered_stig_ocil:questionnaire:1">181788 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1">
181789 ··········<ocil:title>Use·Only·FIPS·140-2·Validated·MACs</ocil:title>181789 ··········<ocil:title>Enable·PAM</ocil:title>
181790 ··········<ocil:actions>181790 ··········<ocil:actions>
181791 ············<ocil:test_action_ref>ocil:ssg-sshd_use_approved_macs_ordered_stig_action:testaction:1</ocil:test_action_ref>181791 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_pam_action:testaction:1</ocil:test_action_ref>
181792 ··········</ocil:actions>181792 ··········</ocil:actions>
181793 ········</ocil:questionnaire>181793 ········</ocil:questionnaire>
181794 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">181794 ········<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_noexec_ocil:questionnaire:1">
181795 ··········<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>181795 ··········<ocil:title>Add·noexec·Option·to·/tmp</ocil:title>
181796 ··········<ocil:actions>181796 ··········<ocil:actions>
181797 ············<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>181797 ············<ocil:test_action_ref>ocil:ssg-mount_option_tmp_noexec_action:testaction:1</ocil:test_action_ref>
181798 ··········</ocil:actions>181798 ··········</ocil:actions>
181799 ········</ocil:questionnaire>181799 ········</ocil:questionnaire>
181800 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_usr_share_ocil:questionnaire:1">181800 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_info_ocil:questionnaire:1">
181801 ··········<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls·in·usr/share</ocil:title>181801 ··········<ocil:title>Set·LogLevel·to·INFO</ocil:title>
181802 ··········<ocil:actions>181802 ··········<ocil:actions>
181803 ············<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_usr_share_action:testaction:1</ocil:test_action_ref>181803 ············<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_info_action:testaction:1</ocil:test_action_ref>
181804 ··········</ocil:actions>181804 ··········</ocil:actions>
181805 ········</ocil:questionnaire>181805 ········</ocil:questionnaire>
181806 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_issue_net_ocil:questionnaire:1">181806 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlinkat_ocil:questionnaire:1">
181807 ··········<ocil:title>Verify·permissions·on·System·Login·Banner·for·Remote·Connections</ocil:title>181807 ··········<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlinkat</ocil:title>
181808 ··········<ocil:actions>181808 ··········<ocil:actions>
181809 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_net_action:testaction:1</ocil:test_action_ref>181809 ············<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlinkat_action:testaction:1</ocil:test_action_ref>
181810 ··········</ocil:actions>181810 ··········</ocil:actions>
181811 ········</ocil:questionnaire>181811 ········</ocil:questionnaire>
181812 ········<ocil:questionnaire·id="ocil:ssg-file_group_ownership_var_log_audit_ocil:questionnaire:1">181812 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_monthly_ocil:questionnaire:1">
181813 ··········<ocil:title>System·Audit·Logs·Must·Be·Group·Owned·By·Root</ocil:title>181813 ··········<ocil:title>Verify·Group·Who·Owns·cron.monthly</ocil:title>
181814 ··········<ocil:actions>181814 ··········<ocil:actions>
181815 ············<ocil:test_action_ref>ocil:ssg-file_group_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>181815 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_monthly_action:testaction:1</ocil:test_action_ref>
181816 ··········</ocil:actions>181816 ··········</ocil:actions>
181817 ········</ocil:questionnaire>181817 ········</ocil:questionnaire>
181818 ········<ocil:questionnaire·id="ocil:ssg-package_cyrus-imapd_removed_ocil:questionnaire:1"> 
181819 ··········<ocil:title>Uninstall·cyrus-imapd·Package</ocil:title>181818 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_audit_rules_ocil:questionnaire:1">
 181819 ··········<ocil:title>Verify·Permissions·on·/etc/audit/audit.rules</ocil:title>
181820 ··········<ocil:actions>181820 ··········<ocil:actions>
181821 ············<ocil:test_action_ref>ocil:ssg-package_cyrus-imapd_removed_action:testaction:1</ocil:test_action_ref>181821 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_audit_rules_action:testaction:1</ocil:test_action_ref>
181822 ··········</ocil:actions>181822 ··········</ocil:actions>
181823 ········</ocil:questionnaire>181823 ········</ocil:questionnaire>
181824 ········<ocil:questionnaire·id="ocil:ssg-package_net-snmp_removed_ocil:questionnaire:1"> 
181825 ··········<ocil:title>Uninstall·net-snmp·Package</ocil:title>181824 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_ocil:questionnaire:1">
 181825 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</ocil:title>
181826 ··········<ocil:actions>181826 ··········<ocil:actions>
181827 ············<ocil:test_action_ref>ocil:ssg-package_net-snmp_removed_action:testaction:1</ocil:test_action_ref>181827 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>
181828 ··········</ocil:actions>181828 ··········</ocil:actions>
181829 ········</ocil:questionnaire>181829 ········</ocil:questionnaire>
181830 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1"> 
181831 ··········<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title>181830 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_delete_ocil:questionnaire:1">
Max diff block lines reached; 1481757/1494008 bytes (99.18%) of diff not shown.
1.36 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ocil.xml
1.36 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ocil.xml
Ordering differences only
    
Offset 3, 10614 lines modifiedOffset 3, 10152 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1"> 
11 ······<ocil:title>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_notifiers_ocil:questionnaire:1">
 11 ······<ocil:title>Enable·checks·on·notifier·call·chains</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_notifiers_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_audit_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1">
17 ······<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>17 ······<ocil:title>Ensure·rsyslog·is·Installed</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-auditd_write_logs_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_sshd_config_ocil:questionnaire:1">
23 ······<ocil:title>Write·Audit·Logs·to·the·Disk</ocil:title>23 ······<ocil:title>Verify·Owner·on·SSH·Server·config·file</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-auditd_write_logs_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_owner_sshd_config_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_legacy_ptys_ocil:questionnaire:1"> 
29 ······<ocil:title>Disable·legacy·(BSD)·PTY·support</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1">
 29 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·openat</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_legacy_ptys_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_macs_ordered_stig_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1">
35 ······<ocil:title>Use·Only·FIPS·140-2·Validated·MACs</ocil:title>35 ······<ocil:title>Enable·PAM</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sshd_use_approved_macs_ordered_stig_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_pam_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_noexec_ocil:questionnaire:1">
41 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>41 ······<ocil:title>Add·noexec·Option·to·/tmp</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_noexec_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_usr_share_ocil:questionnaire:1"> 
47 ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls·in·usr/share</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_info_ocil:questionnaire:1">
 47 ······<ocil:title>Set·LogLevel·to·INFO</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_usr_share_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_info_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_issue_net_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlinkat_ocil:questionnaire:1">
53 ······<ocil:title>Verify·permissions·on·System·Login·Banner·for·Remote·Connections</ocil:title>53 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlinkat</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_net_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlinkat_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_group_ownership_var_log_audit_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_monthly_ocil:questionnaire:1">
59 ······<ocil:title>System·Audit·Logs·Must·Be·Group·Owned·By·Root</ocil:title>59 ······<ocil:title>Verify·Group·Who·Owns·cron.monthly</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_group_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_monthly_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-package_cyrus-imapd_removed_ocil:questionnaire:1"> 
65 ······<ocil:title>Uninstall·cyrus-imapd·Package</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_audit_rules_ocil:questionnaire:1">
 65 ······<ocil:title>Verify·Permissions·on·/etc/audit/audit.rules</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-package_cyrus-imapd_removed_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_audit_rules_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-package_net-snmp_removed_ocil:questionnaire:1"> 
71 ······<ocil:title>Uninstall·net-snmp·Package</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_ocil:questionnaire:1">
 71 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-package_net-snmp_removed_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1"> 
77 ······<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_delete_ocil:questionnaire:1">
 77 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Unloading·-·delete_module</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_delete_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1">
83 ······<ocil:title>Disable·/dev/kmem·virtual·device·support</ocil:title>83 ······<ocil:title>Disable·the·IPv6·protocol</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_devkmem_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_library_dirs_ocil:questionnaire:1"> 
89 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Restrictive·Permissions</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1">
 89 ······<ocil:title>Ensure·logrotate·is·Installed</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-dir_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sudoers_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-package_vsftpd_removed_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions·-·/etc/sudoers</ocil:title>95 ······<ocil:title>Uninstall·vsftpd·Package</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sudoers_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-package_vsftpd_removed_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_macs_ocil:questionnaire:1">
101 ······<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>101 ······<ocil:title>Use·Only·Strong·MACs</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sshd_use_strong_macs_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-journald_compress_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·journald·is·configured·to·compress·large·log·files</ocil:title>107 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-journald_compress_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">
113 ······<ocil:title>Enable·module·signature·verification</ocil:title>113 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-no_forward_files_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-package_ntp_installed_ocil:questionnaire:1">
119 ······<ocil:title>Verify·No·.forward·Files·Exist</ocil:title>119 ······<ocil:title>Install·the·ntp·service</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-no_forward_files_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-package_ntp_installed_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 1416020/1428328 bytes (99.14%) of diff not shown.
924 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ds.xml
924 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:24.04::~~lts~~~">28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:24.04::~~lts~~~">
29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·24.04·(Noble·Numbat)</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·24.04·(Noble·Numbat)</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2404:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2404:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_24-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_24-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·24.04</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·24.04</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Ubuntu·24.04.·It·is·a·rendering·of40 configuration·settings·for·Ubuntu·24.04.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 102298, 15 lines modifiedOffset 102298, 15 lines modified
102298 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2404-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>102298 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2404-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>
102299 ············</xccdf-1.2:check>102299 ············</xccdf-1.2:check>
102300 ··········</xccdf-1.2:Rule>102300 ··········</xccdf-1.2:Rule>
102301 ········</xccdf-1.2:Group>102301 ········</xccdf-1.2:Group>
102302 ······</xccdf-1.2:Group>102302 ······</xccdf-1.2:Group>
102303 ····</xccdf-1.2:Benchmark>102303 ····</xccdf-1.2:Benchmark>
102304 ··</ds:component>102304 ··</ds:component>
102305 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"·timestamp="2025-02-28T20:08:00">102305 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"·timestamp="2025-03-01T22:08:00">
102306 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">102306 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
102307 ······<oval-def:generator>102307 ······<oval-def:generator>
102308 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>102308 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
102309 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>102309 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
102310 ········<oval:schema_version>5.11</oval:schema_version>102310 ········<oval:schema_version>5.11</oval:schema_version>
102311 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>102311 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
102312 ······</oval-def:generator>102312 ······</oval-def:generator>
Offset 123597, 7346 lines modifiedOffset 123597, 6894 lines modified
123597 ············</oval-def:arithmetic>123597 ············</oval-def:arithmetic>
123598 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>123598 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
123599 ··········</oval-def:arithmetic>123599 ··········</oval-def:arithmetic>
123600 ········</oval-def:local_variable>123600 ········</oval-def:local_variable>
123601 ······</oval-def:variables>123601 ······</oval-def:variables>
123602 ····</oval-def:oval_definitions>123602 ····</oval-def:oval_definitions>
123603 ··</ds:component>123603 ··</ds:component>
123604 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"·timestamp="2025-02-28T20:08:00">123604 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"·timestamp="2025-03-01T22:08:00">
123605 ····<ocil:ocil>123605 ····<ocil:ocil>
123606 ······<ocil:generator>123606 ······<ocil:generator>
123607 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>123607 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
123608 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>123608 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
123609 ········<ocil:schema_version>2.0</ocil:schema_version>123609 ········<ocil:schema_version>2.0</ocil:schema_version>
123610 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>123610 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
123611 ······</ocil:generator>123611 ······</ocil:generator>
123612 ······<ocil:questionnaires>123612 ······<ocil:questionnaires>
 123613 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1">
 123614 ··········<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>
123613 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1"> 
123614 ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title> 
123615 ··········<ocil:actions> 
123616 ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref> 
123617 ··········</ocil:actions> 
123618 ········</ocil:questionnaire> 
123619 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
123620 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title> 
123621 ··········<ocil:actions>123615 ··········<ocil:actions>
123622 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>123616 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>
123623 ··········</ocil:actions>123617 ··········</ocil:actions>
123624 ········</ocil:questionnaire>123618 ········</ocil:questionnaire>
123625 ········<ocil:questionnaire·id="ocil:ssg-package_rsync_removed_ocil:questionnaire:1">123619 ········<ocil:questionnaire·id="ocil:ssg-partition_for_tmp_ocil:questionnaire:1">
123626 ··········<ocil:title>Uninstall·rsync·Package</ocil:title>123620 ··········<ocil:title>Ensure·/tmp·Located·On·Separate·Partition</ocil:title>
123627 ··········<ocil:actions>123621 ··········<ocil:actions>
123628 ············<ocil:test_action_ref>ocil:ssg-package_rsync_removed_action:testaction:1</ocil:test_action_ref>123622 ············<ocil:test_action_ref>ocil:ssg-partition_for_tmp_action:testaction:1</ocil:test_action_ref>
123629 ··········</ocil:actions>123623 ··········</ocil:actions>
123630 ········</ocil:questionnaire>123624 ········</ocil:questionnaire>
123631 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_binaries_ocil:questionnaire:1">123625 ········<ocil:questionnaire·id="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1">
123632 ··········<ocil:title>Verify·that·audit·tools·are·owned·by·root</ocil:title>123626 ··········<ocil:title>Verify·Root·Has·A·Primary·GID·0</ocil:title>
123633 ··········<ocil:actions>123627 ··········<ocil:actions>
123634 ············<ocil:test_action_ref>ocil:ssg-file_ownership_audit_binaries_action:testaction:1</ocil:test_action_ref>123628 ············<ocil:test_action_ref>ocil:ssg-accounts_root_gid_zero_action:testaction:1</ocil:test_action_ref>
123635 ··········</ocil:actions>123629 ··········</ocil:actions>
123636 ········</ocil:questionnaire>123630 ········</ocil:questionnaire>
123637 ········<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1"> 
123638 ··········<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>123631 ········<ocil:questionnaire·id="ocil:ssg-aide_periodic_checking_systemd_timer_ocil:questionnaire:1">
 123632 ··········<ocil:title>Configure·Systemd·Timer·Execution·of·AIDE</ocil:title>
123639 ··········<ocil:actions>123633 ··········<ocil:actions>
123640 ············<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>123634 ············<ocil:test_action_ref>ocil:ssg-aide_periodic_checking_systemd_timer_action:testaction:1</ocil:test_action_ref>
123641 ··········</ocil:actions>123635 ··········</ocil:actions>
123642 ········</ocil:questionnaire>123636 ········</ocil:questionnaire>
123643 ········<ocil:questionnaire·id="ocil:ssg-nftables_ensure_default_deny_policy_ocil:questionnaire:1"> 
123644 ··········<ocil:title>Ensure·nftables·Default·Deny·Firewall·Policy</ocil:title>123637 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">
 123638 ··········<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>
123645 ··········<ocil:actions>123639 ··········<ocil:actions>
123646 ············<ocil:test_action_ref>ocil:ssg-nftables_ensure_default_deny_policy_action:testaction:1</ocil:test_action_ref>123640 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
123647 ··········</ocil:actions>123641 ··········</ocil:actions>
123648 ········</ocil:questionnaire>123642 ········</ocil:questionnaire>
123649 ········<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nosuid_ocil:questionnaire:1">123643 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">
123650 ··········<ocil:title>Add·nosuid·Option·to·/dev/shm</ocil:title>123644 ··········<ocil:title>Disable·TIPC·Support</ocil:title>
123651 ··········<ocil:actions>123645 ··········<ocil:actions>
123652 ············<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nosuid_action:testaction:1</ocil:test_action_ref>123646 ············<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>
123653 ··········</ocil:actions>123647 ··········</ocil:actions>
123654 ········</ocil:questionnaire>123648 ········</ocil:questionnaire>
123655 ········<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">123649 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_maxrepeat_ocil:questionnaire:1">
123656 ··········<ocil:title>Install·the·cron·service</ocil:title>123650 ··········<ocil:title>Set·Password·Maximum·Consecutive·Repeating·Characters</ocil:title>
123657 ··········<ocil:actions>123651 ··········<ocil:actions>
123658 ············<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>123652 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_maxrepeat_action:testaction:1</ocil:test_action_ref>
123659 ··········</ocil:actions>123653 ··········</ocil:actions>
123660 ········</ocil:questionnaire>123654 ········</ocil:questionnaire>
123661 ········<ocil:questionnaire·id="ocil:ssg-systemd_journal_upload_url_ocil:questionnaire:1">123655 ········<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_group_ownership_ocil:questionnaire:1">
123662 ··········<ocil:title>Configure·systemd-journal-upload·URL</ocil:title>123656 ··········<ocil:title>User·Initialization·Files·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>
123663 ··········<ocil:actions>123657 ··········<ocil:actions>
123664 ············<ocil:test_action_ref>ocil:ssg-systemd_journal_upload_url_action:testaction:1</ocil:test_action_ref>123658 ············<ocil:test_action_ref>ocil:ssg-accounts_user_dot_group_ownership_action:testaction:1</ocil:test_action_ref>
123665 ··········</ocil:actions>123659 ··········</ocil:actions>
123666 ········</ocil:questionnaire>123660 ········</ocil:questionnaire>
123667 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_issue_ocil:questionnaire:1">123661 ········<ocil:questionnaire·id="ocil:ssg-accounts_root_path_dirs_no_write_ocil:questionnaire:1">
123668 ··········<ocil:title>Verify·ownership·of·System·Login·Banner</ocil:title>123662 ··········<ocil:title>Ensure·that·Root's·Path·Does·Not·Include·World·or·Group-Writable·Directories</ocil:title>
123669 ··········<ocil:actions>123663 ··········<ocil:actions>
123670 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_issue_action:testaction:1</ocil:test_action_ref>123664 ············<ocil:test_action_ref>ocil:ssg-accounts_root_path_dirs_no_write_action:testaction:1</ocil:test_action_ref>
123671 ··········</ocil:actions>123665 ··········</ocil:actions>
123672 ········</ocil:questionnaire>123666 ········</ocil:questionnaire>
123673 ········<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">123667 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_enforce_root_ocil:questionnaire:1">
123674 ··········<ocil:title>Verify·Owner·on·crontab</ocil:title>123668 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Enforce·for·root·User</ocil:title>
123675 ··········<ocil:actions>123669 ··········<ocil:actions>
123676 ············<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref>123670 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_enforce_root_action:testaction:1</ocil:test_action_ref>
123677 ··········</ocil:actions>123671 ··········</ocil:actions>
123678 ········</ocil:questionnaire>123672 ········</ocil:questionnaire>
123679 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">123673 ········<ocil:questionnaire·id="ocil:ssg-file_owner_at_deny_ocil:questionnaire:1">
Max diff block lines reached; 934329/946208 bytes (98.74%) of diff not shown.
881 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ocil.xml
881 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ocil.xml
Ordering differences only
    
Offset 3, 7337 lines modifiedOffset 3, 6885 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
 10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1">
 11 ······<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
17 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-package_rsync_removed_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-partition_for_tmp_ocil:questionnaire:1">
23 ······<ocil:title>Uninstall·rsync·Package</ocil:title>17 ······<ocil:title>Ensure·/tmp·Located·On·Separate·Partition</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-package_rsync_removed_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-partition_for_tmp_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_binaries_ocil:questionnaire:1"> 
29 ······<ocil:title>Verify·that·audit·tools·are·owned·by·root</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1">
 23 ······<ocil:title>Verify·Root·Has·A·Primary·GID·0</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_ownership_audit_binaries_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-accounts_root_gid_zero_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1"> 
35 ······<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-aide_periodic_checking_systemd_timer_ocil:questionnaire:1">
 29 ······<ocil:title>Configure·Systemd·Timer·Execution·of·AIDE</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-aide_periodic_checking_systemd_timer_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-nftables_ensure_default_deny_policy_ocil:questionnaire:1"> 
41 ······<ocil:title>Ensure·nftables·Default·Deny·Firewall·Policy</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">
 35 ······<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-nftables_ensure_default_deny_policy_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nosuid_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">
47 ······<ocil:title>Add·nosuid·Option·to·/dev/shm</ocil:title>41 ······<ocil:title>Disable·TIPC·Support</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nosuid_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_maxrepeat_ocil:questionnaire:1">
53 ······<ocil:title>Install·the·cron·service</ocil:title>47 ······<ocil:title>Set·Password·Maximum·Consecutive·Repeating·Characters</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_maxrepeat_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-systemd_journal_upload_url_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_group_ownership_ocil:questionnaire:1">
59 ······<ocil:title>Configure·systemd-journal-upload·URL</ocil:title>53 ······<ocil:title>User·Initialization·Files·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-systemd_journal_upload_url_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-accounts_user_dot_group_ownership_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_issue_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-accounts_root_path_dirs_no_write_ocil:questionnaire:1">
65 ······<ocil:title>Verify·ownership·of·System·Login·Banner</ocil:title>59 ······<ocil:title>Ensure·that·Root's·Path·Does·Not·Include·World·or·Group-Writable·Directories</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_issue_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-accounts_root_path_dirs_no_write_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_enforce_root_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Owner·on·crontab</ocil:title>65 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Enforce·for·root·User</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_enforce_root_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_at_deny_ocil:questionnaire:1">
77 ······<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>71 ······<ocil:title>Verify·User·Who·Owns·/etc/at.deny·file</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_owner_at_deny_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1">
83 ······<ocil:title>Disable·the·Automounter</ocil:title>77 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_gshadow_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_audit_rules_ocil:questionnaire:1">
89 ······<ocil:title>Verify·Group·Who·Owns·gshadow·File</ocil:title>83 ······<ocil:title>Verify·Permissions·on·/etc/audit/audit.rules</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_gshadow_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_audit_rules_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-set_nftables_loopback_traffic_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_crontab_ocil:questionnaire:1">
95 ······<ocil:title>Set·nftables·Configuration·for·Loopback·Traffic</ocil:title>89 ······<ocil:title>Verify·Group·Who·Owns·Crontab</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-set_nftables_loopback_traffic_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_crontab_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_renameat_ocil:questionnaire:1">
101 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>95 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·renameat</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_renameat_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_ocil:questionnaire:1">
107 ······<ocil:title>Limit·Users'·SSH·Access</ocil:title>101 ······<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_nosuid_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_noexec_ocil:questionnaire:1">
113 ······<ocil:title>Add·nosuid·Option·to·/var</ocil:title>107 ······<ocil:title>Add·noexec·Option·to·/dev/shm</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_nosuid_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_noexec_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1">
 113 ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
Max diff block lines reached; 889949/902383 bytes (98.62%) of diff not shown.
3.73 MB
ssg-debian_0.1.76-1_all.deb
367 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0·····1976·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1976·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0··1230296·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0··1230224·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
3.73 MB
data.tar.xz
3.73 MB
data.tar
734 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
734 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:11">28 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:11">
29 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·11</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·11</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml">oval:ssg-installed_OS_is_debian11:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml">oval:ssg-installed_OS_is_debian11:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Debian·11.·It·is·a·rendering·of40 configuration·settings·for·Debian·11.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 76227, 15 lines modifiedOffset 76227, 15 lines modified
76227 ··············<xccdf-1.2:check-content-ref·href="ssg-debian11-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>76227 ··············<xccdf-1.2:check-content-ref·href="ssg-debian11-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
76228 ············</xccdf-1.2:check>76228 ············</xccdf-1.2:check>
76229 ··········</xccdf-1.2:Rule>76229 ··········</xccdf-1.2:Rule>
76230 ········</xccdf-1.2:Group>76230 ········</xccdf-1.2:Group>
76231 ······</xccdf-1.2:Group>76231 ······</xccdf-1.2:Group>
76232 ····</xccdf-1.2:Benchmark>76232 ····</xccdf-1.2:Benchmark>
76233 ··</ds:component>76233 ··</ds:component>
76234 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-oval.xml"·timestamp="2025-02-28T20:08:00">76234 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-oval.xml"·timestamp="2025-03-01T22:08:00">
76235 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">76235 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
76236 ······<oval-def:generator>76236 ······<oval-def:generator>
76237 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>76237 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
76238 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>76238 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
76239 ········<oval:schema_version>5.11</oval:schema_version>76239 ········<oval:schema_version>5.11</oval:schema_version>
76240 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>76240 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
76241 ······</oval-def:generator>76241 ······</oval-def:generator>
Offset 93180, 5368 lines modifiedOffset 93180, 5359 lines modified
93180 ············</oval-def:arithmetic>93180 ············</oval-def:arithmetic>
93181 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>93181 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
93182 ··········</oval-def:arithmetic>93182 ··········</oval-def:arithmetic>
93183 ········</oval-def:local_variable>93183 ········</oval-def:local_variable>
93184 ······</oval-def:variables>93184 ······</oval-def:variables>
93185 ····</oval-def:oval_definitions>93185 ····</oval-def:oval_definitions>
93186 ··</ds:component>93186 ··</ds:component>
93187 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-ocil.xml"·timestamp="2025-02-28T20:08:00">93187 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-ocil.xml"·timestamp="2025-03-01T22:08:00">
93188 ····<ocil:ocil>93188 ····<ocil:ocil>
93189 ······<ocil:generator>93189 ······<ocil:generator>
93190 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>93190 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
93191 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>93191 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
93192 ········<ocil:schema_version>2.0</ocil:schema_version>93192 ········<ocil:schema_version>2.0</ocil:schema_version>
93193 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>93193 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
93194 ······</ocil:generator>93194 ······</ocil:generator>
93195 ······<ocil:questionnaires>93195 ······<ocil:questionnaires>
93196 ········<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1">93196 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1">
 93197 ··········<ocil:title>Ensure·No·World-Writable·Files·Exist</ocil:title>
93197 ··········<ocil:title>System·Audit·Logs·Must·Have·Mode·0750·or·Less·Permissive</ocil:title> 
93198 ··········<ocil:actions> 
93199 ············<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref> 
93200 ··········</ocil:actions> 
93201 ········</ocil:questionnaire> 
93202 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlinkat_ocil:questionnaire:1"> 
93203 ··········<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlinkat</ocil:title> 
93204 ··········<ocil:actions> 
93205 ············<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlinkat_action:testaction:1</ocil:test_action_ref> 
93206 ··········</ocil:actions> 
93207 ········</ocil:questionnaire> 
93208 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1"> 
93209 ··········<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title> 
93210 ··········<ocil:actions>93198 ··········<ocil:actions>
93211 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>93199 ············<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_world_writable_action:testaction:1</ocil:test_action_ref>
93212 ··········</ocil:actions>93200 ··········</ocil:actions>
93213 ········</ocil:questionnaire>93201 ········</ocil:questionnaire>
93214 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_ocil:questionnaire:1">93202 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rmdir_ocil:questionnaire:1">
93215 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open</ocil:title>93203 ··········<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rmdir</ocil:title>
93216 ··········<ocil:actions>93204 ··········<ocil:actions>
93217 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_action:testaction:1</ocil:test_action_ref>93205 ············<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rmdir_action:testaction:1</ocil:test_action_ref>
93218 ··········</ocil:actions>93206 ··········</ocil:actions>
93219 ········</ocil:questionnaire>93207 ········</ocil:questionnaire>
93220 ········<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1">93208 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1">
93221 ··········<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title>93209 ··········<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions</ocil:title>
93222 ··········<ocil:actions>93210 ··········<ocil:actions>
93223 ············<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>93211 ············<ocil:test_action_ref>ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1</ocil:test_action_ref>
93224 ··········</ocil:actions>93212 ··········</ocil:actions>
93225 ········</ocil:questionnaire>93213 ········</ocil:questionnaire>
93226 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1"> 
93227 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·openat</ocil:title>93214 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">
 93215 ··········<ocil:title>Enable·module·signature·verification</ocil:title>
93228 ··········<ocil:actions>93216 ··········<ocil:actions>
93229 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1</ocil:test_action_ref>93217 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>
93230 ··········</ocil:actions>93218 ··········</ocil:actions>
93231 ········</ocil:questionnaire>93219 ········</ocil:questionnaire>
93232 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_private_key_ocil:questionnaire:1">93220 ········<ocil:questionnaire·id="ocil:ssg-account_use_centralized_automated_auth_ocil:questionnaire:1">
93233 ··········<ocil:title>Verify·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>93221 ··········<ocil:title>Use·Centralized·and·Automated·Authentication</ocil:title>
93234 ··········<ocil:actions>93222 ··········<ocil:actions>
93235 ············<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>93223 ············<ocil:test_action_ref>ocil:ssg-account_use_centralized_automated_auth_action:testaction:1</ocil:test_action_ref>
93236 ··········</ocil:actions>93224 ··········</ocil:actions>
93237 ········</ocil:questionnaire>93225 ········</ocil:questionnaire>
93238 ········<ocil:questionnaire·id="ocil:ssg-sshd_rekey_limit_ocil:questionnaire:1">93226 ········<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1">
93239 ··········<ocil:title>Force·frequent·session·key·renegotiation</ocil:title>93227 ··········<ocil:title>Configure·Polyinstantiation·of·/var/tmp·Directories</ocil:title>
93240 ··········<ocil:actions>93228 ··········<ocil:actions>
93241 ············<ocil:test_action_ref>ocil:ssg-sshd_rekey_limit_action:testaction:1</ocil:test_action_ref>93229 ············<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_var_tmp_action:testaction:1</ocil:test_action_ref>
93242 ··········</ocil:actions>93230 ··········</ocil:actions>
93243 ········</ocil:questionnaire>93231 ········</ocil:questionnaire>
93244 ········<ocil:questionnaire·id="ocil:ssg-sudo_require_authentication_ocil:questionnaire:1">93232 ········<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1">
93245 ··········<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo</ocil:title>93233 ··········<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>
93246 ··········<ocil:actions>93234 ··········<ocil:actions>
93247 ············<ocil:test_action_ref>ocil:ssg-sudo_require_authentication_action:testaction:1</ocil:test_action_ref>93235 ············<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>
93248 ··········</ocil:actions>93236 ··········</ocil:actions>
93249 ········</ocil:questionnaire>93237 ········</ocil:questionnaire>
93250 ········<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">93238 ········<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">
93251 ··········<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>93239 ··········<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>
93252 ··········<ocil:actions>93240 ··········<ocil:actions>
93253 ············<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>93241 ············<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>
93254 ··········</ocil:actions>93242 ··········</ocil:actions>
93255 ········</ocil:questionnaire>93243 ········</ocil:questionnaire>
93256 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1">93244 ········<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">
93257 ··········<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title>93245 ··········<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>
93258 ··········<ocil:actions>93246 ··········<ocil:actions>
93259 ············<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref>93247 ············<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>
93260 ··········</ocil:actions>93248 ··········</ocil:actions>
93261 ········</ocil:questionnaire>93249 ········</ocil:questionnaire>
93262 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1">93250 ········<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">
93263 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>93251 ··········<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>
93264 ··········<ocil:actions>93252 ··········<ocil:actions>
Max diff block lines reached; 739747/751773 bytes (98.40%) of diff not shown.
699 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ocil.xml
699 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ocil.xml
Ordering differences only
    
Offset 3, 5359 lines modifiedOffset 3, 5350 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·No·World-Writable·Files·Exist</ocil:title>
11 ······<ocil:title>System·Audit·Logs·Must·Have·Mode·0750·or·Less·Permissive</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlinkat_ocil:questionnaire:1"> 
17 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlinkat</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlinkat_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1"> 
23 ······<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title> 
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_world_writable_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rmdir_ocil:questionnaire:1">
29 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open</ocil:title>17 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rmdir</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rmdir_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title>23 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1"> 
41 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·openat</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">
 29 ······<ocil:title>Enable·module·signature·verification</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_private_key_ocil:questionnaire:1"> 
47 ······<ocil:title>Verify·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-account_use_centralized_automated_auth_ocil:questionnaire:1">
 35 ······<ocil:title>Use·Centralized·and·Automated·Authentication</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-account_use_centralized_automated_auth_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sshd_rekey_limit_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1">
53 ······<ocil:title>Force·frequent·session·key·renegotiation</ocil:title>41 ······<ocil:title>Configure·Polyinstantiation·of·/var/tmp·Directories</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sshd_rekey_limit_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_var_tmp_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sudo_require_authentication_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo</ocil:title>47 ······<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sudo_require_authentication_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">
65 ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>53 ······<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">
71 ······<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title>59 ······<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
77 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">
 65 ······<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>71 ······<ocil:title>System·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-harden_ssh_client_crypto_policy_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1">
89 ······<ocil:title>Harden·SSH·client·Crypto·Policy</ocil:title>77 ······<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-harden_ssh_client_crypto_policy_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_syslog_ocil:questionnaire:1"> 
95 ······<ocil:title>Verify·Group·Who·Owns·/var/log/syslog·File</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1">
 83 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_syslog_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1"> 
101 ······<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_finit_ocil:questionnaire:1">
 89 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading·-·finit_module</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_finit_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_hibernation_ocil:questionnaire:1"> 
107 ······<ocil:title>Disable·hibernation</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">
 95 ······<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_hibernation_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_ocil:questionnaire:1">
113 ······<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title>101 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1">
 107 ······<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 703619/715807 bytes (98.30%) of diff not shown.
1.19 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ds.xml
1.19 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-oval-definitions-bookworm.xml.bz2"·xlink:href="https://www.debian.org/security/oval/oval-definitions-bookworm.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-oval-definitions-bookworm.xml.bz2"·xlink:href="https://www.debian.org/security/oval/oval-definitions-bookworm.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:12">30 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:12">
31 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·12</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·12</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml">oval:ssg-installed_OS_is_debian12:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml">oval:ssg-installed_OS_is_debian12:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·12</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·12</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Debian·12.·It·is·a·rendering·of42 configuration·settings·for·Debian·12.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 110245, 15 lines modifiedOffset 110245, 15 lines modified
110245 ··············<xccdf-1.2:check-content-ref·href="ssg-debian12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>110245 ··············<xccdf-1.2:check-content-ref·href="ssg-debian12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
110246 ············</xccdf-1.2:check>110246 ············</xccdf-1.2:check>
110247 ··········</xccdf-1.2:Rule>110247 ··········</xccdf-1.2:Rule>
110248 ········</xccdf-1.2:Group>110248 ········</xccdf-1.2:Group>
110249 ······</xccdf-1.2:Group>110249 ······</xccdf-1.2:Group>
110250 ····</xccdf-1.2:Benchmark>110250 ····</xccdf-1.2:Benchmark>
110251 ··</ds:component>110251 ··</ds:component>
110252 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-oval.xml"·timestamp="2025-02-28T20:08:00">110252 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-oval.xml"·timestamp="2025-03-01T22:08:00">
110253 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">110253 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
110254 ······<oval-def:generator>110254 ······<oval-def:generator>
110255 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>110255 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
110256 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>110256 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
110257 ········<oval:schema_version>5.11</oval:schema_version>110257 ········<oval:schema_version>5.11</oval:schema_version>
110258 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>110258 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
110259 ······</oval-def:generator>110259 ······</oval-def:generator>
Offset 140530, 9186 lines modifiedOffset 140530, 9635 lines modified
140530 ············</oval-def:arithmetic>140530 ············</oval-def:arithmetic>
140531 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>140531 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
140532 ··········</oval-def:arithmetic>140532 ··········</oval-def:arithmetic>
140533 ········</oval-def:local_variable>140533 ········</oval-def:local_variable>
140534 ······</oval-def:variables>140534 ······</oval-def:variables>
140535 ····</oval-def:oval_definitions>140535 ····</oval-def:oval_definitions>
140536 ··</ds:component>140536 ··</ds:component>
140537 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-ocil.xml"·timestamp="2025-02-28T20:08:00">140537 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-ocil.xml"·timestamp="2025-03-01T22:08:00">
140538 ····<ocil:ocil>140538 ····<ocil:ocil>
140539 ······<ocil:generator>140539 ······<ocil:generator>
140540 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>140540 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
140541 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>140541 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
140542 ········<ocil:schema_version>2.0</ocil:schema_version>140542 ········<ocil:schema_version>2.0</ocil:schema_version>
140543 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>140543 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
140544 ······</ocil:generator>140544 ······</ocil:generator>
140545 ······<ocil:questionnaires>140545 ······<ocil:questionnaires>
140546 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1">140546 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_kptr_restrict_ocil:questionnaire:1">
 140547 ··········<ocil:title>Restrict·Exposed·Kernel·Pointer·Addresses·Access</ocil:title>
140547 ··········<ocil:title>Enable·checks·on·scatter-gather·(SG)·table·operations</ocil:title> 
140548 ··········<ocil:actions> 
140549 ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_sg_action:testaction:1</ocil:test_action_ref> 
140550 ··········</ocil:actions> 
140551 ········</ocil:questionnaire> 
140552 ········<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1"> 
140553 ··········<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title> 
140554 ··········<ocil:actions>140548 ··········<ocil:actions>
140555 ············<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>140549 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_kptr_restrict_action:testaction:1</ocil:test_action_ref>
140556 ··········</ocil:actions>140550 ··········</ocil:actions>
140557 ········</ocil:questionnaire>140551 ········</ocil:questionnaire>
140558 ········<ocil:questionnaire·id="ocil:ssg-mount_option_boot_noexec_ocil:questionnaire:1">140552 ········<ocil:questionnaire·id="ocil:ssg-harden_ssh_client_crypto_policy_ocil:questionnaire:1">
140559 ··········<ocil:title>Add·noexec·Option·to·/boot</ocil:title>140553 ··········<ocil:title>Harden·SSH·client·Crypto·Policy</ocil:title>
140560 ··········<ocil:actions>140554 ··········<ocil:actions>
140561 ············<ocil:test_action_ref>ocil:ssg-mount_option_boot_noexec_action:testaction:1</ocil:test_action_ref>140555 ············<ocil:test_action_ref>ocil:ssg-harden_ssh_client_crypto_policy_action:testaction:1</ocil:test_action_ref>
140562 ··········</ocil:actions>140556 ··········</ocil:actions>
140563 ········</ocil:questionnaire>140557 ········</ocil:questionnaire>
140564 ········<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_selinux_ocil:questionnaire:1">140558 ········<ocil:questionnaire·id="ocil:ssg-accounts_users_home_files_groupownership_ocil:questionnaire:1">
140565 ··········<ocil:title>Verify·User·Who·Owns·/etc/selinux·Directory</ocil:title>140559 ··········<ocil:title>All·User·Files·and·Directories·In·The·Home·Directory·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>
140566 ··········<ocil:actions>140560 ··········<ocil:actions>
140567 ············<ocil:test_action_ref>ocil:ssg-directory_owner_etc_selinux_action:testaction:1</ocil:test_action_ref>140561 ············<ocil:test_action_ref>ocil:ssg-accounts_users_home_files_groupownership_action:testaction:1</ocil:test_action_ref>
140568 ··········</ocil:actions>140562 ··········</ocil:actions>
140569 ········</ocil:questionnaire>140563 ········</ocil:questionnaire>
140570 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">140564 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_crypttab_ocil:questionnaire:1">
140571 ··········<ocil:title>Verify·User·Who·Owns·Backup·gshadow·File</ocil:title>140565 ··········<ocil:title>Verify·Group·Who·Owns·/etc/crypttab·File</ocil:title>
140572 ··········<ocil:actions>140566 ··········<ocil:actions>
140573 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>140567 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_crypttab_action:testaction:1</ocil:test_action_ref>
140574 ··········</ocil:actions>140568 ··········</ocil:actions>
140575 ········</ocil:questionnaire>140569 ········</ocil:questionnaire>
140576 ········<ocil:questionnaire·id="ocil:ssg-configure_user_data_backups_ocil:questionnaire:1">140570 ········<ocil:questionnaire·id="ocil:ssg-configure_user_data_backups_ocil:questionnaire:1">
140577 ··········<ocil:title>Configure·Backups·of·User·Data</ocil:title>140571 ··········<ocil:title>Configure·Backups·of·User·Data</ocil:title>
140578 ··········<ocil:actions>140572 ··········<ocil:actions>
140579 ············<ocil:test_action_ref>ocil:ssg-configure_user_data_backups_action:testaction:1</ocil:test_action_ref>140573 ············<ocil:test_action_ref>ocil:ssg-configure_user_data_backups_action:testaction:1</ocil:test_action_ref>
140580 ··········</ocil:actions>140574 ··········</ocil:actions>
140581 ········</ocil:questionnaire>140575 ········</ocil:questionnaire>
140582 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1">140576 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1">
 140577 ··········<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>
140583 ··········<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title> 
140584 ··········<ocil:actions> 
140585 ············<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref> 
140586 ··········</ocil:actions> 
140587 ········</ocil:questionnaire> 
140588 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_opasswd_ocil:questionnaire:1"> 
140589 ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/security/opasswd</ocil:title> 
140590 ··········<ocil:actions>140578 ··········<ocil:actions>
140591 ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_opasswd_action:testaction:1</ocil:test_action_ref>140579 ············<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1</ocil:test_action_ref>
140592 ··········</ocil:actions>140580 ··········</ocil:actions>
140593 ········</ocil:questionnaire>140581 ········</ocil:questionnaire>
140594 ········<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1">140582 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_ipsec_secrets_ocil:questionnaire:1">
140595 ··········<ocil:title>Uninstall·rsh-server·Package</ocil:title>140583 ··········<ocil:title>Verify·Group·Who·Owns·/etc/ipsec.secrets·File</ocil:title>
140596 ··········<ocil:actions>140584 ··········<ocil:actions>
140597 ············<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref>140585 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_ipsec_secrets_action:testaction:1</ocil:test_action_ref>
140598 ··········</ocil:actions>140586 ··········</ocil:actions>
140599 ········</ocil:questionnaire>140587 ········</ocil:questionnaire>
140600 ········<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">140588 ········<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1">
140601 ··········<ocil:title>Install·the·cron·service</ocil:title>140589 ··········<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>
140602 ··········<ocil:actions>140590 ··········<ocil:actions>
140603 ············<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>140591 ············<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>
140604 ··········</ocil:actions>140592 ··········</ocil:actions>
140605 ········</ocil:questionnaire>140593 ········</ocil:questionnaire>
140606 ········<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">140594 ········<ocil:questionnaire·id="ocil:ssg-aide_verify_acls_ocil:questionnaire:1">
140607 ··········<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>140595 ··········<ocil:title>Configure·AIDE·to·Verify·Access·Control·Lists·(ACLs)</ocil:title>
140608 ··········<ocil:actions>140596 ··········<ocil:actions>
140609 ············<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>140597 ············<ocil:test_action_ref>ocil:ssg-aide_verify_acls_action:testaction:1</ocil:test_action_ref>
140610 ··········</ocil:actions>140598 ··········</ocil:actions>
140611 ········</ocil:questionnaire>140599 ········</ocil:questionnaire>
140612 ········<ocil:questionnaire·id="ocil:ssg-service_ntp_enabled_ocil:questionnaire:1">140600 ········<ocil:questionnaire·id="ocil:ssg-audit_sudo_log_events_ocil:questionnaire:1">
140613 ··········<ocil:title>Enable·the·NTP·Daemon</ocil:title>140601 ··········<ocil:title>Record·Attempts·to·perform·maintenance·activities</ocil:title>
140614 ··········<ocil:actions>140602 ··········<ocil:actions>
Max diff block lines reached; 1237841/1249445 bytes (99.07%) of diff not shown.
1.14 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ocil.xml
1.14 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ocil.xml
Ordering differences only
    
Offset 3, 9177 lines modifiedOffset 3, 9626 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_kptr_restrict_ocil:questionnaire:1">
 11 ······<ocil:title>Restrict·Exposed·Kernel·Pointer·Addresses·Access</ocil:title>
11 ······<ocil:title>Enable·checks·on·scatter-gather·(SG)·table·operations</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_sg_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1"> 
17 ······<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_kptr_restrict_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_noexec_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-harden_ssh_client_crypto_policy_ocil:questionnaire:1">
23 ······<ocil:title>Add·noexec·Option·to·/boot</ocil:title>17 ······<ocil:title>Harden·SSH·client·Crypto·Policy</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_noexec_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-harden_ssh_client_crypto_policy_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_selinux_ocil:questionnaire:1"> 
29 ······<ocil:title>Verify·User·Who·Owns·/etc/selinux·Directory</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-accounts_users_home_files_groupownership_ocil:questionnaire:1">
 23 ······<ocil:title>All·User·Files·and·Directories·In·The·Home·Directory·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-directory_owner_etc_selinux_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-accounts_users_home_files_groupownership_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_crypttab_ocil:questionnaire:1">
35 ······<ocil:title>Verify·User·Who·Owns·Backup·gshadow·File</ocil:title>29 ······<ocil:title>Verify·Group·Who·Owns·/etc/crypttab·File</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_crypttab_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-configure_user_data_backups_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-configure_user_data_backups_ocil:questionnaire:1">
41 ······<ocil:title>Configure·Backups·of·User·Data</ocil:title>35 ······<ocil:title>Configure·Backups·of·User·Data</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-configure_user_data_backups_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-configure_user_data_backups_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1">
 41 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>
47 ······<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title> 
48 ······<ocil:actions> 
49 ········<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref> 
50 ······</ocil:actions> 
51 ····</ocil:questionnaire> 
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_opasswd_ocil:questionnaire:1"> 
53 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/security/opasswd</ocil:title> 
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_opasswd_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_ipsec_secrets_ocil:questionnaire:1">
59 ······<ocil:title>Uninstall·rsh-server·Package</ocil:title>47 ······<ocil:title>Verify·Group·Who·Owns·/etc/ipsec.secrets·File</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_ipsec_secrets_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1">
65 ······<ocil:title>Install·the·cron·service</ocil:title>53 ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-aide_verify_acls_ocil:questionnaire:1">
71 ······<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>59 ······<ocil:title>Configure·AIDE·to·Verify·Access·Control·Lists·(ACLs)</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-aide_verify_acls_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-service_ntp_enabled_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-audit_sudo_log_events_ocil:questionnaire:1">
77 ······<ocil:title>Enable·the·NTP·Daemon</ocil:title>65 ······<ocil:title>Record·Attempts·to·perform·maintenance·activities</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-service_ntp_enabled_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-audit_sudo_log_events_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_efi_grub2_cfg_ocil:questionnaire:1">
83 ······<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title>71 ······<ocil:title>Verify·the·UEFI·Boot·Loader·grub.cfg·Group·Ownership</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_efi_grub2_cfg_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_sudo_ocil:questionnaire:1"> 
89 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·sudo</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1">
 77 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_sudo_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_shutdown_ocil:questionnaire:1"> 
95 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·shutdown</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
 83 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_shutdown_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_private_key_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">
101 ······<ocil:title>Verify·Permissions·on·SSH·Server·Private·*_key·Key·Files</ocil:title>89 ······<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_private_key_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1"> 
107 ······<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_hardened_usercopy_fallback_ocil:questionnaire:1">
 95 ······<ocil:title>Do·not·allow·usercopy·whitelist·violations·to·fallback·to·object·size</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-kernel_config_hardened_usercopy_fallback_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·auditd·Collects·Unauthorized·Access·Attempts·to·Files·(unsuccessful)</ocil:title>101 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_yama_ptrace_scope_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-auditd_write_logs_ocil:questionnaire:1">
119 ······<ocil:title>Restrict·usage·of·ptrace·to·descendant·processes</ocil:title>107 ······<ocil:title>Write·Audit·Logs·to·the·Disk</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_yama_ptrace_scope_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-auditd_write_logs_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>110 ······</ocil:actions>
123 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
Max diff block lines reached; 1179902/1192051 bytes (98.98%) of diff not shown.
79.6 MB
ssg-nondebian_0.1.76-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0····18196·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0····18192·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0·37082368·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0·37082048·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
79.6 MB
data.tar.xz
79.6 MB
data.tar
3.49 KB
./usr/share/doc/ssg-nondebian/table-ol7-nistrefs-stig.html
    
Offset 8559, 18 lines modifiedOffset 8559, 18 lines modified
000216e0:·616e·6420·7573·6520·7468·6520·696e·666f··and·use·the·info000216e0:·616e·6420·7573·6520·7468·6520·696e·666f··and·use·the·info
000216f0:·726d·6174·696f·6e20·746f·2070·6f74·656e··rmation·to·poten000216f0:·726d·6174·696f·6e20·746f·2070·6f74·656e··rmation·to·poten
00021700:·7469·616c·6c79·2063·6f6d·7072·6f6d·6973··tially·compromis00021700:·7469·616c·6c79·2063·6f6d·7072·6f6d·6973··tially·compromis
00021710:·6520·7468·6520·696e·7465·6772·6974·7920··e·the·integrity·00021710:·6520·7468·6520·696e·7465·6772·6974·7920··e·the·integrity·
00021720:·6f66·2074·6865·2073·7973·7465·6d20·616e··of·the·system·an00021720:·6f66·2074·6865·2073·7973·7465·6d20·616e··of·the·system·an
00021730:·640a·6e65·7477·6f72·6b28·7329·2e0a·2020··d.network(s)..··00021730:·640a·6e65·7477·6f72·6b28·7329·2e0a·2020··d.network(s)..··
00021740:·3c2f·7464·3e0a·2020·3c74·643e·7661·725f··</td>.··<td>var_00021740:·3c2f·7464·3e0a·2020·3c74·643e·7661·725f··</td>.··<td>var_
00021750:·736e·6d70·645f·726f·5f73·7472·696e·673d··snmpd_ro_string=00021750:·736e·6d70·645f·7277·5f73·7472·696e·673d··snmpd_rw_string=
00021760:·6368·616e·6765·6d65·726f·3c62·722f·3e76··changemero<br/>v00021760:·6368·616e·6765·6d65·7277·3c62·722f·3e76··changemerw<br/>v
00021770:·6172·5f73·6e6d·7064·5f72·775f·7374·7269··ar_snmpd_rw_stri00021770:·6172·5f73·6e6d·7064·5f72·6f5f·7374·7269··ar_snmpd_ro_stri
00021780:·6e67·3d63·6861·6e67·656d·6572·773c·2f74··ng=changemerw</t00021780:·6e67·3d63·6861·6e67·656d·6572·6f3c·2f74··ng=changemero</t
00021790:·643e·0a3c·2f74·723e·0a3c·7472·3e0a·2020··d>.</tr>.<tr>.··00021790:·643e·0a3c·2f74·723e·0a3c·7472·3e0a·2020··d>.</tr>.<tr>.··
000217a0:·3c74·643e·5343·2d35·3c2f·7464·3e0a·2020··<td>SC-5</td>.··000217a0:·3c74·643e·5343·2d35·3c2f·7464·3e0a·2020··<td>SC-5</td>.··
000217b0:·3c74·643e·4e2f·413c·2f74·643e·0a20·203c··<td>N/A</td>.··<000217b0:·3c74·643e·4e2f·413c·2f74·643e·0a20·203c··<td>N/A</td>.··<
000217c0:·7464·3e43·6f6e·6669·6775·7265·204b·6572··td>Configure·Ker000217c0:·7464·3e43·6f6e·6669·6775·7265·204b·6572··td>Configure·Ker
000217d0:·6e65·6c20·746f·2052·6174·6520·4c69·6d69··nel·to·Rate·Limi000217d0:·6e65·6c20·746f·2052·6174·6520·4c69·6d69··nel·to·Rate·Limi
000217e0:·7420·5365·6e64·696e·6720·6f66·2044·7570··t·Sending·of·Dup000217e0:·7420·5365·6e64·696e·6720·6f66·2044·7570··t·Sending·of·Dup
000217f0:·6c69·6361·7465·2054·4350·2041·636b·6e6f··licate·TCP·Ackno000217f0:·6c69·6361·7465·2054·4350·2041·636b·6e6f··licate·TCP·Ackno
1.87 KB
html2text {}
    
Offset 2919, 16 lines modifiedOffset 2919, 16 lines modified
2919 ··············································································network·management2919 ··············································································network·management
2920 ··············································································protocol·(SNMP)2920 ··············································································protocol·(SNMP)
2921 ··············································································community·strings2921 ··············································································community·strings
2922 ··············································································must·be·changed·to2922 ··············································································must·be·changed·to
2923 ··································Edit·/etc/snmp/snmpd.conf,·remove·or·change·maintain·security.2923 ··································Edit·/etc/snmp/snmpd.conf,·remove·or·change·maintain·security.
2924 ··································the·default·community·strings·of·public·and·If·the·service·is2924 ··································the·default·community·strings·of·public·and·If·the·service·is
2925 ··································private.·This·profile·configures·new·read-··running·with·the2925 ··································private.·This·profile·configures·new·read-··running·with·the
2926 ········N/·Ensure·Default·SNMP····only·community·string·to·changemero·and·····default·············var_snmpd_ro_string=changemero2926 ········N/·Ensure·Default·SNMP····only·community·string·to·changemero·and·····default·············var_snmpd_rw_string=changemerw
2927 IA-5(e)·A··Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·····var_snmpd_rw_string=changemerw2927 IA-5(e)·A··Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·····var_snmpd_ro_string=changemero
2928 ··································Once·the·default·community·strings·have·····then·anyone·can2928 ··································Once·the·default·community·strings·have·····then·anyone·can
2929 ··································been·changed,·restart·the·SNMP·service:·····gather·data·about2929 ··································been·changed,·restart·the·SNMP·service:·····gather·data·about
2930 ··································$·sudo·systemctl·restart·snmpd··············the·system·and·the2930 ··································$·sudo·systemctl·restart·snmpd··············the·system·and·the
2931 ··············································································network·and·use·the2931 ··············································································network·and·use·the
2932 ··············································································information·to2932 ··············································································information·to
2933 ··············································································potentially2933 ··············································································potentially
2934 ··············································································compromise·the2934 ··············································································compromise·the
3.21 KB
./usr/share/doc/ssg-nondebian/table-ol8-nistrefs-ospp.html
    
Offset 4133, 15 lines modifiedOffset 4133, 15 lines modified
4133 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>4133 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>
4134 ··</td>4134 ··</td>
4135 ··<td·xml:lang="en-US">4135 ··<td·xml:lang="en-US">
4136 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4136 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4137 time-based·limit,·effects·of·potential·attacks·against4137 time-based·limit,·effects·of·potential·attacks·against
4138 encryption·keys·are·limited.4138 encryption·keys·are·limited.
4139 ··</td>4139 ··</td>
4140 ··<td>var_rekey_limit_time=1hour<br/>var_rekey_limit_size=1G</td>4140 ··<td>var_rekey_limit_size=1G<br/>var_rekey_limit_time=1hour</td>
4141 </tr>4141 </tr>
4142 <tr>4142 <tr>
4143 ··<td></td>4143 ··<td></td>
4144 ··<td>N/A</td>4144 ··<td>N/A</td>
4145 ··<td>SSH·server·uses·strong·entropy·to·seed</td>4145 ··<td>SSH·server·uses·strong·entropy·to·seed</td>
4146 ··<td·xml:lang="en-US">4146 ··<td·xml:lang="en-US">
4147 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.4147 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.
2.48 KB
html2text {}
    
Offset 3401, 16 lines modifiedOffset 3401, 16 lines modified
3401 ··················································································································generator·used·by3401 ··················································································································generator·used·by
3402 ··················································································································SSH·would·be·known3402 ··················································································································SSH·would·be·known
3403 ··················································································································to·potential3403 ··················································································································to·potential
3404 ··················································································································attackers.3404 ··················································································································attackers.
3405 ··················································································································By·decreasing·the3405 ··················································································································By·decreasing·the
3406 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the3406 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the
3407 ········Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and3407 ········Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and
3408 ·····N/·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_time=1hour3408 ·····N/·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_size=1G
3409 ·····A··renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_size=1G3409 ·····A··renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_time=1hour
3410 ·························RekeyLimit·1G·1hour······································································potential·attacks3410 ·························RekeyLimit·1G·1hour······································································potential·attacks
3411 ··················································································································against·encryption3411 ··················································································································against·encryption
3412 ··················································································································keys·are·limited.3412 ··················································································································keys·are·limited.
3413 ··················································································································SSH·implementation3413 ··················································································································SSH·implementation
3414 ··················································································································in·Oracle·Linux·83414 ··················································································································in·Oracle·Linux·8
3415 ··················································································································uses·the·openssl3415 ··················································································································uses·the·openssl
3416 ··················································································································library,·which3416 ··················································································································library,·which
3.49 KB
./usr/share/doc/ssg-nondebian/table-ol8-nistrefs-stig.html
    
Offset 24427, 17 lines modifiedOffset 24427, 17 lines modified
0005f6a0:·6e67·0a74·696d·652d·6261·7365·6420·6c69··ng.time-based·li0005f6a0:·6e67·0a74·696d·652d·6261·7365·6420·6c69··ng.time-based·li
0005f6b0:·6d69·742c·2065·6666·6563·7473·206f·6620··mit,·effects·of·0005f6b0:·6d69·742c·2065·6666·6563·7473·206f·6620··mit,·effects·of·
0005f6c0:·706f·7465·6e74·6961·6c20·6174·7461·636b··potential·attack0005f6c0:·706f·7465·6e74·6961·6c20·6174·7461·636b··potential·attack
0005f6d0:·7320·6167·6169·6e73·740a·656e·6372·7970··s·against.encryp0005f6d0:·7320·6167·6169·6e73·740a·656e·6372·7970··s·against.encryp
0005f6e0:·7469·6f6e·206b·6579·7320·6172·6520·6c69··tion·keys·are·li0005f6e0:·7469·6f6e·206b·6579·7320·6172·6520·6c69··tion·keys·are·li
0005f6f0:·6d69·7465·642e·0a20·203c·2f74·643e·0a20··mited..··</td>.·0005f6f0:·6d69·7465·642e·0a20·203c·2f74·643e·0a20··mited..··</td>.·
0005f700:·203c·7464·3e76·6172·5f72·656b·6579·5f6c···<td>var_rekey_l0005f700:·203c·7464·3e76·6172·5f72·656b·6579·5f6c···<td>var_rekey_l
 0005f710:·696d·6974·5f73·697a·653d·3147·3c62·722f··imit_size=1G<br/
 0005f720:·3e76·6172·5f72·656b·6579·5f6c·696d·6974··>var_rekey_limit
0005f710:·696d·6974·5f74·696d·653d·3168·6f75·723c··imit_time=1hour<0005f730:·5f74·696d·653d·3168·6f75·723c·2f74·643e··_time=1hour</td>
0005f720:·6272·2f3e·7661·725f·7265·6b65·795f·6c69··br/>var_rekey_li 
0005f730:·6d69·745f·7369·7a65·3d31·473c·2f74·643e··mit_size=1G</td> 
0005f740:·0a3c·2f74·723e·0a3c·7472·3e0a·2020·3c74··.</tr>.<tr>.··<t0005f740:·0a3c·2f74·723e·0a3c·7472·3e0a·2020·3c74··.</tr>.<tr>.··<t
0005f750:·643e·3c2f·7464·3e0a·2020·3c74·643e·4e2f··d></td>.··<td>N/0005f750:·643e·3c2f·7464·3e0a·2020·3c74·643e·4e2f··d></td>.··<td>N/
0005f760:·413c·2f74·643e·0a20·203c·7464·3e53·5348··A</td>.··<td>SSH0005f760:·413c·2f74·643e·0a20·203c·7464·3e53·5348··A</td>.··<td>SSH
0005f770:·2073·6572·7665·7220·7573·6573·2073·7472···server·uses·str0005f770:·2073·6572·7665·7220·7573·6573·2073·7472···server·uses·str
0005f780:·6f6e·6720·656e·7472·6f70·7920·746f·2073··ong·entropy·to·s0005f780:·6f6e·6720·656e·7472·6f70·7920·746f·2073··ong·entropy·to·s
0005f790:·6565·643c·2f74·643e·0a20·203c·7464·2078··eed</td>.··<td·x0005f790:·6565·643c·2f74·643e·0a20·203c·7464·2078··eed</td>.··<td·x
0005f7a0:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">0005f7a0:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">
2.0 KB
html2text {}
    
Offset 7774, 16 lines modifiedOffset 7774, 16 lines modified
7774 ·································private·key.··········································system·where·the7774 ·································private·key.··········································system·where·the
7775 ·······················································································associated·public7775 ·······················································································associated·public
7776 ·······················································································key·has·been7776 ·······················································································key·has·been
7777 ·······················································································installed.7777 ·······················································································installed.
7778 ·································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the7778 ·································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the
7779 ·································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the7779 ·································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the
7780 ···········Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and7780 ···········Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and
7781 ········N/·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_time=1hour7781 ········N/·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_size=1G
7782 ········A··renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_size=1G7782 ········A··renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_time=1hour
7783 ·································following·line·in·/etc/ssh/sshd_config:···············potential·attacks7783 ·································following·line·in·/etc/ssh/sshd_config:···············potential·attacks
7784 ·································RekeyLimit·1G·1hour···································against·encryption7784 ·································RekeyLimit·1G·1hour···································against·encryption
7785 ·······················································································keys·are·limited.7785 ·······················································································keys·are·limited.
7786 ·······················································································SSH·implementation7786 ·······················································································SSH·implementation
7787 ·······················································································in·Oracle·Linux·87787 ·······················································································in·Oracle·Linux·8
7788 ·······················································································uses·the·openssl7788 ·······················································································uses·the·openssl
7789 ·······················································································library,·which7789 ·······················································································library,·which
6.48 KB
./usr/share/doc/ssg-nondebian/table-rhel8-nistrefs-ospp.html
    
Offset 4075, 15 lines modifiedOffset 4075, 15 lines modified
4075 <tt>RekeyLimit</tt>.4075 <tt>RekeyLimit</tt>.
4076 ··</td>4076 ··</td>
4077 ··<td·xml:lang="en-US">4077 ··<td·xml:lang="en-US">
4078 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4078 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4079 time-based·limit,·effects·of·potential·attacks·against4079 time-based·limit,·effects·of·potential·attacks·against
4080 encryption·keys·are·limited.4080 encryption·keys·are·limited.
4081 ··</td>4081 ··</td>
4082 ··<td>var_ssh_client_rekey_limit_size=1G<br/>var_ssh_client_rekey_limit_time=1hour</td>4082 ··<td>var_ssh_client_rekey_limit_time=1hour<br/>var_ssh_client_rekey_limit_size=1G</td>
4083 </tr>4083 </tr>
4084 <tr>4084 <tr>
4085 ··<td></td>4085 ··<td></td>
4086 ··<td>CCE-83349-1</td>4086 ··<td>CCE-83349-1</td>
4087 ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td>4087 ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td>
4088 ··<td·xml:lang="en-US">4088 ··<td·xml:lang="en-US">
4089 To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure4089 To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure
Offset 4138, 15 lines modifiedOffset 4138, 15 lines modified
4138 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>4138 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>
4139 ··</td>4139 ··</td>
4140 ··<td·xml:lang="en-US">4140 ··<td·xml:lang="en-US">
4141 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4141 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4142 time-based·limit,·effects·of·potential·attacks·against4142 time-based·limit,·effects·of·potential·attacks·against
4143 encryption·keys·are·limited.4143 encryption·keys·are·limited.
4144 ··</td>4144 ··</td>
4145 ··<td>var_rekey_limit_time=1hour<br/>var_rekey_limit_size=1G</td>4145 ··<td>var_rekey_limit_size=1G<br/>var_rekey_limit_time=1hour</td>
4146 </tr>4146 </tr>
4147 <tr>4147 <tr>
4148 ··<td></td>4148 ··<td></td>
4149 ··<td>CCE-82462-3</td>4149 ··<td>CCE-82462-3</td>
4150 ··<td>SSH·server·uses·strong·entropy·to·seed</td>4150 ··<td>SSH·server·uses·strong·entropy·to·seed</td>
4151 ··<td·xml:lang="en-US">4151 ··<td·xml:lang="en-US">
4152 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.4152 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.
5.11 KB
html2text {}
    
Offset 3356, 16 lines modifiedOffset 3356, 16 lines modified
3356 ······················································································································options,·which·can3356 ······················································································································options,·which·can
3357 ······················································································································help·protect3357 ······················································································································help·protect
3358 ······················································································································programs·which·use3358 ······················································································································programs·which·use
3359 ······················································································································it.3359 ······················································································································it.
3360 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the3360 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the
3361 ·····························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the3361 ·····························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the
3362 ·····CCE-···Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and3362 ·····CCE-···Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and
3363 ·····82880-·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_size=1G3363 ·····82880-·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_time=1hour
3364 ·····6······renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_time=1hour3364 ·····6······renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_size=1G
3365 ············for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks3365 ············for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks
3366 ·····························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption3366 ·····························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption
3367 ·····························containing·definition·of·RekeyLimit.·····················································keys·are·limited.3367 ·····························containing·definition·of·RekeyLimit.·····················································keys·are·limited.
3368 ······················································································································Some·SSH3368 ······················································································································Some·SSH
3369 ······················································································································implementations·use3369 ······················································································································implementations·use
3370 ······················································································································the·openssl·library3370 ······················································································································the·openssl·library
3371 ······················································································································for·entropy,·which3371 ······················································································································for·entropy,·which
Offset 3416, 16 lines modifiedOffset 3416, 16 lines modified
3416 ······················································································································generator·used·by3416 ······················································································································generator·used·by
3417 ······················································································································SSH·would·be·known3417 ······················································································································SSH·would·be·known
3418 ······················································································································to·potential3418 ······················································································································to·potential
3419 ······················································································································attackers.3419 ······················································································································attackers.
3420 ······················································································································By·decreasing·the3420 ······················································································································By·decreasing·the
3421 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the3421 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the
3422 ·····CCE-···Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and3422 ·····CCE-···Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and
3423 ·····82177-·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_time=1hour3423 ·····82177-·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_size=1G
3424 ·····7······renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_size=1G3424 ·····7······renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_time=1hour
3425 ·····························RekeyLimit·1G·1hour······································································potential·attacks3425 ·····························RekeyLimit·1G·1hour······································································potential·attacks
3426 ······················································································································against·encryption3426 ······················································································································against·encryption
3427 ······················································································································keys·are·limited.3427 ······················································································································keys·are·limited.
3428 ······················································································································SSH·implementation3428 ······················································································································SSH·implementation
3429 ······················································································································in·Red·Hat3429 ······················································································································in·Red·Hat
3430 ······················································································································Enterprise·Linux·83430 ······················································································································Enterprise·Linux·8
3431 ······················································································································uses·the·openssl3431 ······················································································································uses·the·openssl
3.56 KB
./usr/share/doc/ssg-nondebian/table-rhel8-nistrefs-stig.html
    
Offset 24277, 17 lines modifiedOffset 24277, 17 lines modified
0005ed40:·696e·670a·7469·6d65·2d62·6173·6564·206c··ing.time-based·l0005ed40:·696e·670a·7469·6d65·2d62·6173·6564·206c··ing.time-based·l
0005ed50:·696d·6974·2c20·6566·6665·6374·7320·6f66··imit,·effects·of0005ed50:·696d·6974·2c20·6566·6665·6374·7320·6f66··imit,·effects·of
0005ed60:·2070·6f74·656e·7469·616c·2061·7474·6163···potential·attac0005ed60:·2070·6f74·656e·7469·616c·2061·7474·6163···potential·attac
0005ed70:·6b73·2061·6761·696e·7374·0a65·6e63·7279··ks·against.encry0005ed70:·6b73·2061·6761·696e·7374·0a65·6e63·7279··ks·against.encry
0005ed80:·7074·696f·6e20·6b65·7973·2061·7265·206c··ption·keys·are·l0005ed80:·7074·696f·6e20·6b65·7973·2061·7265·206c··ption·keys·are·l
0005ed90:·696d·6974·6564·2e0a·2020·3c2f·7464·3e0a··imited..··</td>.0005ed90:·696d·6974·6564·2e0a·2020·3c2f·7464·3e0a··imited..··</td>.
0005eda0:·2020·3c74·643e·7661·725f·7265·6b65·795f····<td>var_rekey_0005eda0:·2020·3c74·643e·7661·725f·7265·6b65·795f····<td>var_rekey_
0005edb0:·6c69·6d69·745f·7369·7a65·3d31·473c·6272··limit_size=1G<br0005edb0:·6c69·6d69·745f·7469·6d65·3d31·686f·7572··limit_time=1hour
0005edc0:·2f3e·7661·725f·7265·6b65·795f·6c69·6d69··/>var_rekey_limi 
0005edd0:·745f·7469·6d65·3d31·686f·7572·3c2f·7464··t_time=1hour</td0005edc0:·3c62·722f·3e76·6172·5f72·656b·6579·5f6c··<br/>var_rekey_l
 0005edd0:·696d·6974·5f73·697a·653d·3147·3c2f·7464··imit_size=1G</td
0005ede0:·3e0a·3c2f·7472·3e0a·3c74·723e·0a20·203c··>.</tr>.<tr>.··<0005ede0:·3e0a·3c2f·7472·3e0a·3c74·723e·0a20·203c··>.</tr>.<tr>.··<
0005edf0:·7464·3e3c·2f74·643e·0a20·203c·7464·3e43··td></td>.··<td>C0005edf0:·7464·3e3c·2f74·643e·0a20·203c·7464·3e43··td></td>.··<td>C
0005ee00:·4345·2d38·3234·3632·2d33·3c2f·7464·3e0a··CE-82462-3</td>.0005ee00:·4345·2d38·3234·3632·2d33·3c2f·7464·3e0a··CE-82462-3</td>.
0005ee10:·2020·3c74·643e·5353·4820·7365·7276·6572····<td>SSH·server0005ee10:·2020·3c74·643e·5353·4820·7365·7276·6572····<td>SSH·server
0005ee20:·2075·7365·7320·7374·726f·6e67·2065·6e74···uses·strong·ent0005ee20:·2075·7365·7320·7374·726f·6e67·2065·6e74···uses·strong·ent
0005ee30:·726f·7079·2074·6f20·7365·6564·3c2f·7464··ropy·to·seed</td0005ee30:·726f·7079·2074·6f20·7365·6564·3c2f·7464··ropy·to·seed</td
0005ee40:·3e0a·2020·3c74·6420·786d·6c3a·6c61·6e67··>.··<td·xml:lang0005ee40:·3e0a·2020·3c74·6420·786d·6c3a·6c61·6e67··>.··<td·xml:lang
2.07 KB
html2text {}
    
Offset 7644, 16 lines modifiedOffset 7644, 16 lines modified
7644 ·····································corresponding·private·key.····························system·where·the7644 ·····································corresponding·private·key.····························system·where·the
7645 ···························································································associated·public7645 ···························································································associated·public
7646 ···························································································key·has·been7646 ···························································································key·has·been
7647 ···························································································installed.7647 ···························································································installed.
7648 ·····································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the7648 ·····································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the
7649 ·····································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the7649 ·····································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the
7650 ········CCE-···Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and7650 ········CCE-···Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and
7651 ········82177-·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_size=1G7651 ········82177-·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_time=1hour
7652 ········7······renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_time=1hour7652 ········7······renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_size=1G
7653 ·····································following·line·in·/etc/ssh/sshd_config:···············potential·attacks7653 ·····································following·line·in·/etc/ssh/sshd_config:···············potential·attacks
7654 ·····································RekeyLimit·1G·1hour···································against·encryption7654 ·····································RekeyLimit·1G·1hour···································against·encryption
7655 ···························································································keys·are·limited.7655 ···························································································keys·are·limited.
7656 ···························································································SSH·implementation7656 ···························································································SSH·implementation
7657 ···························································································in·Red·Hat7657 ···························································································in·Red·Hat
7658 ···························································································Enterprise·Linux·87658 ···························································································Enterprise·Linux·8
7659 ···························································································uses·the·openssl7659 ···························································································uses·the·openssl
1.31 KB
./usr/share/scap-security-guide/tailoring/ol8_stig_delta_tailoring.xml
1.18 KB
./usr/share/scap-security-guide/tailoring/ol8_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2025-02-28T20:08:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Oracle·Linux·8</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Oracle·Linux·8</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Oracle·Linux·8·V2R3.</xccdf-1.2:description>7 DISA·STIG·for·Oracle·Linux·8·V2R3.</xccdf-1.2:description>
8 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs"·selected="false"/>8 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs"·selected="false"/>
9 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay"·selected="false"/>9 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay"·selected="false"/>
10 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions"·selected="false"/>10 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions"·selected="false"/>
1.12 KB
./usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml
999 B
./usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2025-02-28T20:08:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V2R2.7 DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V2R2.
  
8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·this8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·this
9 configuration·baseline·is·applicable·to·the·operating·system·tier·of9 configuration·baseline·is·applicable·to·the·operating·system·tier·of
1.12 KB
./usr/share/scap-security-guide/tailoring/rhel9_stig_delta_tailoring.xml
999 B
./usr/share/scap-security-guide/tailoring/rhel9_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2025-02-28T20:08:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Red·Hat·Enterprise·Linux·9·V2R3.7 DISA·STIG·for·Red·Hat·Enterprise·Linux·9·V2R3.
  
8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·9,·this8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·9,·this
9 configuration·baseline·is·applicable·to·the·operating·system·tier·of9 configuration·baseline·is·applicable·to·the·operating·system·tier·of
754 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ds.xml
754 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:amazon_linux:2023">28 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:amazon_linux:2023">
29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Linux·2023</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Linux·2023</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml">oval:ssg-installed_OS_is_al2023:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml">oval:ssg-installed_OS_is_al2023:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_AL-2023"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_AL-2023"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Linux·2023</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Linux·2023</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Amazon·Linux·2023.·It·is·a·rendering·of40 configuration·settings·for·Amazon·Linux·2023.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 98811, 15 lines modifiedOffset 98811, 15 lines modified
98811 ··············<xccdf-1.2:check-content-ref·href="ssg-al2023-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/>98811 ··············<xccdf-1.2:check-content-ref·href="ssg-al2023-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/>
98812 ············</xccdf-1.2:check>98812 ············</xccdf-1.2:check>
98813 ··········</xccdf-1.2:Rule>98813 ··········</xccdf-1.2:Rule>
98814 ········</xccdf-1.2:Group>98814 ········</xccdf-1.2:Group>
98815 ······</xccdf-1.2:Group>98815 ······</xccdf-1.2:Group>
98816 ····</xccdf-1.2:Benchmark>98816 ····</xccdf-1.2:Benchmark>
98817 ··</ds:component>98817 ··</ds:component>
98818 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-oval.xml"·timestamp="2025-02-28T20:08:00">98818 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-oval.xml"·timestamp="2025-03-01T22:08:00">
98819 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">98819 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
98820 ······<oval-def:generator>98820 ······<oval-def:generator>
98821 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>98821 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
98822 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>98822 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
98823 ········<oval:schema_version>5.11</oval:schema_version>98823 ········<oval:schema_version>5.11</oval:schema_version>
98824 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>98824 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
98825 ······</oval-def:generator>98825 ······</oval-def:generator>
Offset 117150, 3304 lines modifiedOffset 117150, 3304 lines modified
117150 ············</oval-def:arithmetic>117150 ············</oval-def:arithmetic>
117151 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>117151 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
117152 ··········</oval-def:arithmetic>117152 ··········</oval-def:arithmetic>
117153 ········</oval-def:local_variable>117153 ········</oval-def:local_variable>
117154 ······</oval-def:variables>117154 ······</oval-def:variables>
117155 ····</oval-def:oval_definitions>117155 ····</oval-def:oval_definitions>
117156 ··</ds:component>117156 ··</ds:component>
117157 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-ocil.xml"·timestamp="2025-02-28T20:08:00">117157 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-ocil.xml"·timestamp="2025-03-01T22:08:00">
117158 ····<ocil:ocil>117158 ····<ocil:ocil>
117159 ······<ocil:generator>117159 ······<ocil:generator>
117160 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>117160 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
117161 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>117161 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
117162 ········<ocil:schema_version>2.0</ocil:schema_version>117162 ········<ocil:schema_version>2.0</ocil:schema_version>
117163 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>117163 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
117164 ······</ocil:generator>117164 ······</ocil:generator>
117165 ······<ocil:questionnaires>117165 ······<ocil:questionnaires>
117166 ········<ocil:questionnaire·id="ocil:ssg-file_owner_sshd_config_ocil:questionnaire:1">117166 ········<ocil:questionnaire·id="ocil:ssg-partition_for_home_ocil:questionnaire:1">
117167 ··········<ocil:title>Verify·Owner·on·SSH·Server·config·file</ocil:title>117167 ··········<ocil:title>Ensure·/home·Located·On·Separate·Partition</ocil:title>
117168 ··········<ocil:actions>117168 ··········<ocil:actions>
117169 ············<ocil:test_action_ref>ocil:ssg-file_owner_sshd_config_action:testaction:1</ocil:test_action_ref>117169 ············<ocil:test_action_ref>ocil:ssg-partition_for_home_action:testaction:1</ocil:test_action_ref>
117170 ··········</ocil:actions>117170 ··········</ocil:actions>
117171 ········</ocil:questionnaire>117171 ········</ocil:questionnaire>
117172 ········<ocil:questionnaire·id="ocil:ssg-file_cron_deny_not_exist_ocil:questionnaire:1">117172 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">
117173 ··········<ocil:title>Ensure·that·/etc/cron.deny·does·not·exist</ocil:title>117173 ··········<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
117174 ··········<ocil:actions>117174 ··········<ocil:actions>
117175 ············<ocil:test_action_ref>ocil:ssg-file_cron_deny_not_exist_action:testaction:1</ocil:test_action_ref>117175 ············<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
117176 ··········</ocil:actions>117176 ··········</ocil:actions>
117177 ········</ocil:questionnaire>117177 ········</ocil:questionnaire>
117178 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_crontab_ocil:questionnaire:1"> 
117179 ··········<ocil:title>Verify·Group·Who·Owns·Crontab</ocil:title>117178 ········<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_deny_ocil:questionnaire:1">
 117179 ··········<ocil:title>Lock·Accounts·After·Failed·Password·Attempts</ocil:title>
117180 ··········<ocil:actions>117180 ··········<ocil:actions>
117181 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_crontab_action:testaction:1</ocil:test_action_ref>117181 ············<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_deny_action:testaction:1</ocil:test_action_ref>
117182 ··········</ocil:actions>117182 ··········</ocil:actions>
117183 ········</ocil:questionnaire>117183 ········</ocil:questionnaire>
117184 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">117184 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_daily_ocil:questionnaire:1">
117185 ··········<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>117185 ··········<ocil:title>Verify·Owner·on·cron.daily</ocil:title>
117186 ··········<ocil:actions>117186 ··········<ocil:actions>
117187 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>117187 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_daily_action:testaction:1</ocil:test_action_ref>
117188 ··········</ocil:actions>117188 ··········</ocil:actions>
117189 ········</ocil:questionnaire>117189 ········</ocil:questionnaire>
117190 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1">117190 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_renameat_ocil:questionnaire:1">
117191 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>117191 ··········<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·renameat</ocil:title>
117192 ··········<ocil:actions>117192 ··········<ocil:actions>
117193 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref>117193 ············<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_renameat_action:testaction:1</ocil:test_action_ref>
117194 ··········</ocil:actions>117194 ··········</ocil:actions>
117195 ········</ocil:questionnaire>117195 ········</ocil:questionnaire>
117196 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1"> 
117197 ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>117196 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">
 117197 ··········<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>
117198 ··········<ocil:actions>117198 ··········<ocil:actions>
117199 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>117199 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>
117200 ··········</ocil:actions>117200 ··········</ocil:actions>
117201 ········</ocil:questionnaire>117201 ········</ocil:questionnaire>
117202 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1">117202 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_cramfs_disabled_ocil:questionnaire:1">
117203 ··········<ocil:title>Enable·SSH·Warning·Banner</ocil:title>117203 ··········<ocil:title>Disable·Mounting·of·cramfs</ocil:title>
117204 ··········<ocil:actions>117204 ··········<ocil:actions>
117205 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref>117205 ············<ocil:test_action_ref>ocil:ssg-kernel_module_cramfs_disabled_action:testaction:1</ocil:test_action_ref>
117206 ··········</ocil:actions>117206 ··········</ocil:actions>
117207 ········</ocil:questionnaire>117207 ········</ocil:questionnaire>
117208 ········<ocil:questionnaire·id="ocil:ssg-account_password_pam_faillock_password_auth_ocil:questionnaire:1">117208 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_at_allow_ocil:questionnaire:1">
117209 ··········<ocil:title>Configure·the·Use·of·the·pam_faillock.so·Module·in·the·/etc/pam.d/password-auth·File.</ocil:title>117209 ··········<ocil:title>Verify·Group·Who·Owns·/etc/at.allow·file</ocil:title>
117210 ··········<ocil:actions>117210 ··········<ocil:actions>
117211 ············<ocil:test_action_ref>ocil:ssg-account_password_pam_faillock_password_auth_action:testaction:1</ocil:test_action_ref>117211 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_at_allow_action:testaction:1</ocil:test_action_ref>
117212 ··········</ocil:actions>117212 ··········</ocil:actions>
117213 ········</ocil:questionnaire>117213 ········</ocil:questionnaire>
117214 ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_nosuid_ocil:questionnaire:1">117214 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1">
117215 ··········<ocil:title>Add·nosuid·Option·to·/var/log</ocil:title>117215 ··········<ocil:title>Make·the·auditd·Configuration·Immutable</ocil:title>
117216 ··········<ocil:actions>117216 ··········<ocil:actions>
117217 ············<ocil:test_action_ref>ocil:ssg-mount_option_var_log_nosuid_action:testaction:1</ocil:test_action_ref>117217 ············<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_action:testaction:1</ocil:test_action_ref>
117218 ··········</ocil:actions>117218 ··········</ocil:actions>
117219 ········</ocil:questionnaire>117219 ········</ocil:questionnaire>
117220 ········<ocil:questionnaire·id="ocil:ssg-package_bind_removed_ocil:questionnaire:1">117220 ········<ocil:questionnaire·id="ocil:ssg-package_nftables_installed_ocil:questionnaire:1">
117221 ··········<ocil:title>Uninstall·bind·Package</ocil:title>117221 ··········<ocil:title>Install·nftables·Package</ocil:title>
117222 ··········<ocil:actions>117222 ··········<ocil:actions>
117223 ············<ocil:test_action_ref>ocil:ssg-package_bind_removed_action:testaction:1</ocil:test_action_ref>117223 ············<ocil:test_action_ref>ocil:ssg-package_nftables_installed_action:testaction:1</ocil:test_action_ref>
117224 ··········</ocil:actions>117224 ··········</ocil:actions>
117225 ········</ocil:questionnaire>117225 ········</ocil:questionnaire>
117226 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1"> 
117227 ··········<ocil:title>Verify·Group·Ownership·of·Message·of·the·Day·Banner</ocil:title>117226 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1">
 117227 ··········<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>
117228 ··········<ocil:actions>117228 ··········<ocil:actions>
117229 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref>117229 ············<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>
117230 ··········</ocil:actions>117230 ··········</ocil:actions>
117231 ········</ocil:questionnaire>117231 ········</ocil:questionnaire>
117232 ········<ocil:questionnaire·id="ocil:ssg-file_permission_user_init_files_ocil:questionnaire:1">117232 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_gshadow_ocil:questionnaire:1">
117233 ··········<ocil:title>Ensure·All·User·Initialization·Files·Have·Mode·0740·Or·Less·Permissive</ocil:title>117233 ··········<ocil:title>Verify·Group·Who·Owns·Backup·gshadow·File</ocil:title>
Max diff block lines reached; 759532/771608 bytes (98.43%) of diff not shown.
718 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ocil.xml
718 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ocil.xml
Ordering differences only
    
Offset 3, 3295 lines modifiedOffset 3, 3295 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_sshd_config_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-partition_for_home_ocil:questionnaire:1">
11 ······<ocil:title>Verify·Owner·on·SSH·Server·config·file</ocil:title>11 ······<ocil:title>Ensure·/home·Located·On·Separate·Partition</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-file_owner_sshd_config_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-partition_for_home_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_cron_deny_not_exist_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">
17 ······<ocil:title>Ensure·that·/etc/cron.deny·does·not·exist</ocil:title>17 ······<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_cron_deny_not_exist_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_crontab_ocil:questionnaire:1"> 
23 ······<ocil:title>Verify·Group·Who·Owns·Crontab</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_deny_ocil:questionnaire:1">
 23 ······<ocil:title>Lock·Accounts·After·Failed·Password·Attempts</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_crontab_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_deny_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_daily_ocil:questionnaire:1">
29 ······<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>29 ······<ocil:title>Verify·Owner·on·cron.daily</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_daily_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_renameat_ocil:questionnaire:1">
35 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>35 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·renameat</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_renameat_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1"> 
41 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">
 41 ······<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1"> 
47 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_cramfs_disabled_ocil:questionnaire:1">
 47 ······<ocil:title>Disable·Mounting·of·cramfs</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-kernel_module_cramfs_disabled_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-account_password_pam_faillock_password_auth_ocil:questionnaire:1"> 
53 ······<ocil:title>Configure·the·Use·of·the·pam_faillock.so·Module·in·the·/etc/pam.d/password-auth·File.</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_at_allow_ocil:questionnaire:1">
 53 ······<ocil:title>Verify·Group·Who·Owns·/etc/at.allow·file</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-account_password_pam_faillock_password_auth_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_at_allow_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_nosuid_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1">
59 ······<ocil:title>Add·nosuid·Option·to·/var/log</ocil:title>59 ······<ocil:title>Make·the·auditd·Configuration·Immutable</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_nosuid_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-package_bind_removed_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-package_nftables_installed_ocil:questionnaire:1">
65 ······<ocil:title>Uninstall·bind·Package</ocil:title>65 ······<ocil:title>Install·nftables·Package</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-package_bind_removed_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-package_nftables_installed_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1"> 
71 ······<ocil:title>Verify·Group·Ownership·of·Message·of·the·Day·Banner</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1">
 71 ······<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_permission_user_init_files_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_gshadow_ocil:questionnaire:1">
77 ······<ocil:title>Ensure·All·User·Initialization·Files·Have·Mode·0740·Or·Less·Permissive</ocil:title>77 ······<ocil:title>Verify·Group·Who·Owns·Backup·gshadow·File</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_permission_user_init_files_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_issue_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Permissions·on·gshadow·File</ocil:title>83 ······<ocil:title>Verify·Group·Ownership·of·System·Login·Banner</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_gshadow_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_nolisten_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·Group</ocil:title>89 ······<ocil:title>Ensure·rsyslog·Does·Not·Accept·Remote·Messages·Unless·Acting·As·Log·Server</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_ungroupowned_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-rsyslog_nolisten_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_interactive_home_directory_exists_ocil:questionnaire:1"> 
95 ······<ocil:title>All·Interactive·Users·Home·Directories·Must·Exist</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_dccp_disabled_ocil:questionnaire:1">
 95 ······<ocil:title>Disable·DCCP·Support</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-accounts_user_interactive_home_directory_exists_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-kernel_module_dccp_disabled_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_audit_nosuid_ocil:questionnaire:1"> 
101 ······<ocil:title>Add·nosuid·Option·to·/var/log/audit</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1">
 101 ······<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_nosuid_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-service_snmpd_disabled_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1">
107 ······<ocil:title>Disable·snmpd·Service</ocil:title>107 ······<ocil:title>Verify·Group·Who·Owns·cron.hourly</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-service_snmpd_disabled_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_max_life_existing_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>113 ······<ocil:title>Set·Existing·Passwords·Maximum·Age</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_existing_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_ocil:questionnaire:1">
119 ······<ocil:title>Verify·User·Who·Owns·Backup·gshadow·File</ocil:title>119 ······<ocil:title>Ensure·/var·Located·On·Separate·Partition</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 722380/734706 bytes (98.32%) of diff not shown.
899 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds.xml
899 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:2">28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:2">
29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·2</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·2</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml">oval:ssg-installed_OS_is_alinux2:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml">oval:ssg-installed_OS_is_alinux2:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-2"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-2"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·2</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·2</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Alibaba·Cloud·Linux·2.·It·is·a·rendering·of40 configuration·settings·for·Alibaba·Cloud·Linux·2.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 58534, 15 lines modifiedOffset 58534, 15 lines modified
58534 ··············<xccdf-1.2:check-content-ref·href="ssg-alinux2-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>58534 ··············<xccdf-1.2:check-content-ref·href="ssg-alinux2-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
58535 ············</xccdf-1.2:check>58535 ············</xccdf-1.2:check>
58536 ··········</xccdf-1.2:Rule>58536 ··········</xccdf-1.2:Rule>
58537 ········</xccdf-1.2:Group>58537 ········</xccdf-1.2:Group>
58538 ······</xccdf-1.2:Group>58538 ······</xccdf-1.2:Group>
58539 ····</xccdf-1.2:Benchmark>58539 ····</xccdf-1.2:Benchmark>
58540 ··</ds:component>58540 ··</ds:component>
58541 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-oval.xml"·timestamp="2025-02-28T20:08:00">58541 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-oval.xml"·timestamp="2025-03-01T22:08:00">
58542 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">58542 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
58543 ······<oval-def:generator>58543 ······<oval-def:generator>
58544 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>58544 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
58545 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>58545 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
58546 ········<oval:schema_version>5.11</oval:schema_version>58546 ········<oval:schema_version>5.11</oval:schema_version>
58547 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>58547 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
58548 ······</oval-def:generator>58548 ······</oval-def:generator>
Offset 79715, 2768 lines modifiedOffset 79715, 2768 lines modified
79715 ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/>79715 ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/>
79716 ··········</oval-def:regex_capture>79716 ··········</oval-def:regex_capture>
79717 ········</oval-def:local_variable>79717 ········</oval-def:local_variable>
79718 ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/>79718 ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/>
79719 ······</oval-def:variables>79719 ······</oval-def:variables>
79720 ····</oval-def:oval_definitions>79720 ····</oval-def:oval_definitions>
79721 ··</ds:component>79721 ··</ds:component>
79722 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-ocil.xml"·timestamp="2025-02-28T20:08:00">79722 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-ocil.xml"·timestamp="2025-03-01T22:08:00">
79723 ····<ocil:ocil>79723 ····<ocil:ocil>
79724 ······<ocil:generator>79724 ······<ocil:generator>
79725 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>79725 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
79726 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>79726 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
79727 ········<ocil:schema_version>2.0</ocil:schema_version>79727 ········<ocil:schema_version>2.0</ocil:schema_version>
79728 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>79728 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
79729 ······</ocil:generator>79729 ······</ocil:generator>
79730 ······<ocil:questionnaires>79730 ······<ocil:questionnaires>
79731 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1">79731 ········<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1">
 79732 ··········<ocil:title>Remove·NIS·Client</ocil:title>
79732 ··········<ocil:title>Verify·Permissions·on·crontab</ocil:title> 
79733 ··········<ocil:actions> 
79734 ············<ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref> 
79735 ··········</ocil:actions> 
79736 ········</ocil:questionnaire> 
79737 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_ocil:questionnaire:1"> 
79738 ··········<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title> 
79739 ··········<ocil:actions>79733 ··········<ocil:actions>
79740 ············<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_action:testaction:1</ocil:test_action_ref>79734 ············<ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref>
79741 ··········</ocil:actions>79735 ··········</ocil:actions>
79742 ········</ocil:questionnaire>79736 ········</ocil:questionnaire>
79743 ········<ocil:questionnaire·id="ocil:ssg-coredump_disable_storage_ocil:questionnaire:1"> 
79744 ··········<ocil:title>Disable·storing·core·dump</ocil:title>79737 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1">
 79738 ··········<ocil:title>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</ocil:title>
79745 ··········<ocil:actions>79739 ··········<ocil:actions>
79746 ············<ocil:test_action_ref>ocil:ssg-coredump_disable_storage_action:testaction:1</ocil:test_action_ref>79740 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1</ocil:test_action_ref>
79747 ··········</ocil:actions>79741 ··········</ocil:actions>
79748 ········</ocil:questionnaire>79742 ········</ocil:questionnaire>
79749 ········<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1">79743 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_filter_ocil:questionnaire:1">
79750 ··········<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title>79744 ··········<ocil:title>Enable·use·of·Berkeley·Packet·Filter·with·seccomp</ocil:title>
79751 ··········<ocil:actions>79745 ··········<ocil:actions>
79752 ············<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>79746 ············<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_filter_action:testaction:1</ocil:test_action_ref>
79753 ··········</ocil:actions>79747 ··········</ocil:actions>
79754 ········</ocil:questionnaire>79748 ········</ocil:questionnaire>
79755 ········<ocil:questionnaire·id="ocil:ssg-sshd_print_last_log_ocil:questionnaire:1">79749 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_brk_ocil:questionnaire:1">
79756 ··········<ocil:title>Enable·SSH·Print·Last·Log</ocil:title>79750 ··········<ocil:title>Disable·compatibility·with·brk()</ocil:title>
79757 ··········<ocil:actions>79751 ··········<ocil:actions>
79758 ············<ocil:test_action_ref>ocil:ssg-sshd_print_last_log_action:testaction:1</ocil:test_action_ref>79752 ············<ocil:test_action_ref>ocil:ssg-kernel_config_compat_brk_action:testaction:1</ocil:test_action_ref>
79759 ··········</ocil:actions>79753 ··········</ocil:actions>
79760 ········</ocil:questionnaire>79754 ········</ocil:questionnaire>
79761 ········<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1">79755 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1">
79762 ··········<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title>79756 ··········<ocil:title>Verify·Permissions·on·shadow·File</ocil:title>
79763 ··········<ocil:actions>79757 ··········<ocil:actions>
79764 ············<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref>79758 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shadow_action:testaction:1</ocil:test_action_ref>
79765 ··········</ocil:actions>79759 ··········</ocil:actions>
79766 ········</ocil:questionnaire>79760 ········</ocil:questionnaire>
79767 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">79761 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_grub2_cfg_ocil:questionnaire:1">
79768 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>79762 ··········<ocil:title>Verify·/boot/grub2/grub.cfg·Permissions</ocil:title>
79769 ··········<ocil:actions>79763 ··········<ocil:actions>
79770 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>79764 ············<ocil:test_action_ref>ocil:ssg-file_permissions_grub2_cfg_action:testaction:1</ocil:test_action_ref>
79771 ··········</ocil:actions>79765 ··········</ocil:actions>
79772 ········</ocil:questionnaire>79766 ········</ocil:questionnaire>
79773 ········<ocil:questionnaire·id="ocil:ssg-account_disable_post_pw_expiration_ocil:questionnaire:1">79767 ········<ocil:questionnaire·id="ocil:ssg-selinux_confinement_of_daemons_ocil:questionnaire:1">
79774 ··········<ocil:title>Set·Account·Expiration·Following·Inactivity</ocil:title>79768 ··········<ocil:title>Ensure·No·Daemons·are·Unconfined·by·SELinux</ocil:title>
79775 ··········<ocil:actions>79769 ··········<ocil:actions>
79776 ············<ocil:test_action_ref>ocil:ssg-account_disable_post_pw_expiration_action:testaction:1</ocil:test_action_ref>79770 ············<ocil:test_action_ref>ocil:ssg-selinux_confinement_of_daemons_action:testaction:1</ocil:test_action_ref>
79777 ··········</ocil:actions>79771 ··········</ocil:actions>
79778 ········</ocil:questionnaire>79772 ········</ocil:questionnaire>
79779 ········<ocil:questionnaire·id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1"> 
79780 ··········<ocil:title>Limit·the·Number·of·Concurrent·Login·Sessions·Allowed·Per·User</ocil:title>79773 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_messages_ocil:questionnaire:1">
 79774 ··········<ocil:title>Verify·Permissions·on·/var/log/messages·File</ocil:title>
79781 ··········<ocil:actions>79775 ··········<ocil:actions>
79782 ············<ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>79776 ············<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_messages_action:testaction:1</ocil:test_action_ref>
79783 ··········</ocil:actions>79777 ··········</ocil:actions>
79784 ········</ocil:questionnaire>79778 ········</ocil:questionnaire>
79785 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1">79779 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_slub_debug_ocil:questionnaire:1">
79786 ··········<ocil:title>System·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>79780 ··········<ocil:title>Enable·SLUB·debugging·support</ocil:title>
79787 ··········<ocil:actions>79781 ··········<ocil:actions>
79788 ············<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>79782 ············<ocil:test_action_ref>ocil:ssg-kernel_config_slub_debug_action:testaction:1</ocil:test_action_ref>
79789 ··········</ocil:actions>79783 ··········</ocil:actions>
79790 ········</ocil:questionnaire>79784 ········</ocil:questionnaire>
79791 ········<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">79785 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">
79792 ··········<ocil:title>Disable·XDMCP·in·GDM</ocil:title>79786 ··········<ocil:title>Enable·support·for·BUG()</ocil:title>
79793 ··········<ocil:actions>79787 ··········<ocil:actions>
79794 ············<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>79788 ············<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref>
79795 ··········</ocil:actions>79789 ··········</ocil:actions>
79796 ········</ocil:questionnaire>79790 ········</ocil:questionnaire>
79797 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_ocil:questionnaire:1"> 
79798 ··········<ocil:title>Limit·Password·Reuse:·password-auth</ocil:title>79791 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">
Max diff block lines reached; 908782/920611 bytes (98.72%) of diff not shown.
857 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ocil.xml
857 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ocil.xml
Ordering differences only
    
Offset 3, 2759 lines modifiedOffset 3, 2759 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1">
 11 ······<ocil:title>Remove·NIS·Client</ocil:title>
11 ······<ocil:title>Verify·Permissions·on·crontab</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_ocil:questionnaire:1"> 
17 ······<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-coredump_disable_storage_ocil:questionnaire:1"> 
23 ······<ocil:title>Disable·storing·core·dump</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1">
 17 ······<ocil:title>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-coredump_disable_storage_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_filter_ocil:questionnaire:1">
29 ······<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title>23 ······<ocil:title>Enable·use·of·Berkeley·Packet·Filter·with·seccomp</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_filter_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sshd_print_last_log_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_brk_ocil:questionnaire:1">
35 ······<ocil:title>Enable·SSH·Print·Last·Log</ocil:title>29 ······<ocil:title>Disable·compatibility·with·brk()</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sshd_print_last_log_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_compat_brk_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1"> 
41 ······<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1">
 35 ······<ocil:title>Verify·Permissions·on·shadow·File</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shadow_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_grub2_cfg_ocil:questionnaire:1">
47 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>41 ······<ocil:title>Verify·/boot/grub2/grub.cfg·Permissions</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_permissions_grub2_cfg_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-account_disable_post_pw_expiration_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-selinux_confinement_of_daemons_ocil:questionnaire:1">
53 ······<ocil:title>Set·Account·Expiration·Following·Inactivity</ocil:title>47 ······<ocil:title>Ensure·No·Daemons·are·Unconfined·by·SELinux</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-account_disable_post_pw_expiration_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-selinux_confinement_of_daemons_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1"> 
59 ······<ocil:title>Limit·the·Number·of·Concurrent·Login·Sessions·Allowed·Per·User</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_messages_ocil:questionnaire:1">
 53 ······<ocil:title>Verify·Permissions·on·/var/log/messages·File</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_messages_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_slub_debug_ocil:questionnaire:1">
65 ······<ocil:title>System·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>59 ······<ocil:title>Enable·SLUB·debugging·support</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_slub_debug_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">
71 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>65 ······<ocil:title>Enable·support·for·BUG()</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_ocil:questionnaire:1"> 
77 ······<ocil:title>Limit·Password·Reuse:·password-auth</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">
 71 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-chronyd_run_as_chrony_user_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·that·chronyd·is·running·under·chrony·user·account</ocil:title>77 ······<ocil:title>Ensure·that·/etc/at.deny·does·not·exist</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-chronyd_run_as_chrony_user_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-configure_ssh_crypto_policy_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_hashes_ocil:questionnaire:1">
89 ······<ocil:title>Configure·SSH·to·use·System·Crypto·Policy</ocil:title>83 ······<ocil:title>Verify·File·Hashes·with·RPM</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-configure_ssh_crypto_policy_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-rpm_verify_hashes_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sudoers_explicit_command_args_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sudoers_explicit_command_args_ocil:questionnaire:1">
95 ······<ocil:title>Explicit·arguments·in·sudo·specifications</ocil:title>89 ······<ocil:title>Explicit·arguments·in·sudo·specifications</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sudoers_explicit_command_args_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sudoers_explicit_command_args_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-service_oddjobd_disabled_ocil:questionnaire:1"> 
101 ······<ocil:title>Disable·Odd·Job·Daemon·(oddjobd)</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lchown_ocil:questionnaire:1">
 95 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lchown</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-service_oddjobd_disabled_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lchown_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_kptr_restrict_ocil:questionnaire:1"> 
107 ······<ocil:title>Restrict·Exposed·Kernel·Pointer·Addresses·Access</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_dir_ocil:questionnaire:1">
 101 ······<ocil:title>Account·Lockouts·Must·Persist</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_kptr_restrict_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-service_sshd_disabled_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_allow_ocil:questionnaire:1">
113 ······<ocil:title>Disable·SSH·Server·If·Possible</ocil:title>107 ······<ocil:title>Verify·Group·Who·Owns·/etc/cron.allow·file</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-service_sshd_disabled_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_allow_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-no_direct_root_logins_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1">
119 ······<ocil:title>Direct·root·Logins·Not·Allowed</ocil:title>113 ······<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-no_direct_root_logins_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
Max diff block lines reached; 866003/877623 bytes (98.68%) of diff not shown.
897 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds.xml
896 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:3">28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:3">
29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·3</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·3</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml">oval:ssg-installed_OS_is_alinux3:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml">oval:ssg-installed_OS_is_alinux3:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-3"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-3"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·3</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·3</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Alibaba·Cloud·Linux·3.·It·is·a·rendering·of40 configuration·settings·for·Alibaba·Cloud·Linux·3.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 57666, 15 lines modifiedOffset 57666, 15 lines modified
57666 ··············<xccdf-1.2:check-content-ref·href="ssg-alinux3-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>57666 ··············<xccdf-1.2:check-content-ref·href="ssg-alinux3-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
57667 ············</xccdf-1.2:check>57667 ············</xccdf-1.2:check>
57668 ··········</xccdf-1.2:Rule>57668 ··········</xccdf-1.2:Rule>
57669 ········</xccdf-1.2:Group>57669 ········</xccdf-1.2:Group>
57670 ······</xccdf-1.2:Group>57670 ······</xccdf-1.2:Group>
57671 ····</xccdf-1.2:Benchmark>57671 ····</xccdf-1.2:Benchmark>
57672 ··</ds:component>57672 ··</ds:component>
57673 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-oval.xml"·timestamp="2025-02-28T20:08:00">57673 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-oval.xml"·timestamp="2025-03-01T22:08:00">
57674 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">57674 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
57675 ······<oval-def:generator>57675 ······<oval-def:generator>
57676 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>57676 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
57677 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>57677 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
57678 ········<oval:schema_version>5.11</oval:schema_version>57678 ········<oval:schema_version>5.11</oval:schema_version>
57679 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>57679 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
57680 ······</oval-def:generator>57680 ······</oval-def:generator>
Offset 77997, 5412 lines modifiedOffset 77997, 5412 lines modified
77997 ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/>77997 ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/>
77998 ··········</oval-def:regex_capture>77998 ··········</oval-def:regex_capture>
77999 ········</oval-def:local_variable>77999 ········</oval-def:local_variable>
78000 ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/>78000 ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/>
78001 ······</oval-def:variables>78001 ······</oval-def:variables>
78002 ····</oval-def:oval_definitions>78002 ····</oval-def:oval_definitions>
78003 ··</ds:component>78003 ··</ds:component>
78004 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-ocil.xml"·timestamp="2025-02-28T20:08:00">78004 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-ocil.xml"·timestamp="2025-03-01T22:08:00">
78005 ····<ocil:ocil>78005 ····<ocil:ocil>
78006 ······<ocil:generator>78006 ······<ocil:generator>
78007 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>78007 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
78008 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>78008 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
78009 ········<ocil:schema_version>2.0</ocil:schema_version>78009 ········<ocil:schema_version>2.0</ocil:schema_version>
78010 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>78010 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
78011 ······</ocil:generator>78011 ······</ocil:generator>
78012 ······<ocil:questionnaires>78012 ······<ocil:questionnaires>
78013 ········<ocil:questionnaire·id="ocil:ssg-package_libreswan_installed_ocil:questionnaire:1"> 
78014 ··········<ocil:title>Install·libreswan·Package</ocil:title> 
78015 ··········<ocil:actions> 
78016 ············<ocil:test_action_ref>ocil:ssg-package_libreswan_installed_action:testaction:1</ocil:test_action_ref> 
78017 ··········</ocil:actions> 
78018 ········</ocil:questionnaire> 
78019 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_allow_ocil:questionnaire:1">78013 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">
78020 ··········<ocil:title>Verify·Group·Who·Owns·/etc/cron.allow·file</ocil:title>78014 ··········<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>
78021 ··········<ocil:actions> 
78022 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_allow_action:testaction:1</ocil:test_action_ref> 
78023 ··········</ocil:actions> 
78024 ········</ocil:questionnaire> 
78025 ········<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1"> 
78026 ··········<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title> 
78027 ··········<ocil:actions> 
78028 ············<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref> 
78029 ··········</ocil:actions> 
78030 ········</ocil:questionnaire> 
78031 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_ocil:questionnaire:1"> 
78032 ··········<ocil:title>Disable·IPv6·Addressing·on·IPv6·Interfaces·by·Default</ocil:title> 
78033 ··········<ocil:actions>78015 ··········<ocil:actions>
78034 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_action:testaction:1</ocil:test_action_ref>78016 ············<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>
78035 ··········</ocil:actions>78017 ··········</ocil:actions>
78036 ········</ocil:questionnaire>78018 ········</ocil:questionnaire>
78037 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_acpi_custom_method_ocil:questionnaire:1"> 
78038 ··········<ocil:title>Do·not·allow·ACPI·methods·to·be·inserted/replaced·at·run·time</ocil:title>78019 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_gshadow_ocil:questionnaire:1">
 78020 ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/gshadow</ocil:title>
78039 ··········<ocil:actions>78021 ··········<ocil:actions>
78040 ············<ocil:test_action_ref>ocil:ssg-kernel_config_acpi_custom_method_action:testaction:1</ocil:test_action_ref>78022 ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_gshadow_action:testaction:1</ocil:test_action_ref>
78041 ··········</ocil:actions>78023 ··········</ocil:actions>
78042 ········</ocil:questionnaire>78024 ········</ocil:questionnaire>
78043 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chmod_ocil:questionnaire:1">78025 ········<ocil:questionnaire·id="ocil:ssg-selinux_confinement_of_daemons_ocil:questionnaire:1">
78044 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chmod</ocil:title>78026 ··········<ocil:title>Ensure·No·Daemons·are·Unconfined·by·SELinux</ocil:title>
78045 ··········<ocil:actions>78027 ··········<ocil:actions>
78046 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chmod_action:testaction:1</ocil:test_action_ref>78028 ············<ocil:test_action_ref>ocil:ssg-selinux_confinement_of_daemons_action:testaction:1</ocil:test_action_ref>
78047 ··········</ocil:actions>78029 ··········</ocil:actions>
78048 ········</ocil:questionnaire>78030 ········</ocil:questionnaire>
78049 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">78031 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">
78050 ··········<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>78032 ··········<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>
78051 ··········<ocil:actions>78033 ··········<ocil:actions>
78052 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>78034 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>
78053 ··········</ocil:actions>78035 ··········</ocil:actions>
78054 ········</ocil:questionnaire>78036 ········</ocil:questionnaire>
78055 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1"> 
78056 ··········<ocil:title>Disable·Kerberos·Authentication</ocil:title> 
78057 ··········<ocil:actions> 
78058 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref> 
78059 ··········</ocil:actions> 
78060 ········</ocil:questionnaire> 
78061 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1">78037 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1">
78062 ··········<ocil:title>Make·the·auditd·Configuration·Immutable</ocil:title>78038 ··········<ocil:title>Verify·Permissions·on·crontab</ocil:title>
78063 ··········<ocil:actions>78039 ··········<ocil:actions>
78064 ············<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_action:testaction:1</ocil:test_action_ref>78040 ············<ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref>
78065 ··········</ocil:actions>78041 ··········</ocil:actions>
78066 ········</ocil:questionnaire>78042 ········</ocil:questionnaire>
78067 ········<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_init_ocil:questionnaire:1">78043 ········<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1">
78068 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·init</ocil:title>78044 ··········<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title>
78069 ··········<ocil:actions>78045 ··········<ocil:actions>
78070 ············<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_init_action:testaction:1</ocil:test_action_ref>78046 ············<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref>
78071 ··········</ocil:actions>78047 ··········</ocil:actions>
78072 ········</ocil:questionnaire>78048 ········</ocil:questionnaire>
78073 ········<ocil:questionnaire·id="ocil:ssg-package_xinetd_removed_ocil:questionnaire:1">78049 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1">
78074 ··········<ocil:title>Uninstall·xinetd·Package</ocil:title>78050 ··········<ocil:title>Kernel·panic·timeout</ocil:title>
78075 ··········<ocil:actions>78051 ··········<ocil:actions>
78076 ············<ocil:test_action_ref>ocil:ssg-package_xinetd_removed_action:testaction:1</ocil:test_action_ref>78052 ············<ocil:test_action_ref>ocil:ssg-kernel_config_panic_timeout_action:testaction:1</ocil:test_action_ref>
78077 ··········</ocil:actions>78053 ··········</ocil:actions>
78078 ········</ocil:questionnaire>78054 ········</ocil:questionnaire>
78079 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1">78055 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1">
78080 ··········<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions</ocil:title>78056 ··········<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
78081 ··········<ocil:actions>78057 ··········<ocil:actions>
78082 ············<ocil:test_action_ref>ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1</ocil:test_action_ref>78058 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 906853/917860 bytes (98.80%) of diff not shown.
855 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ocil.xml
855 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ocil.xml
Ordering differences only
    
Offset 3, 5403 lines modifiedOffset 3, 5403 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-package_libreswan_installed_ocil:questionnaire:1"> 
11 ······<ocil:title>Install·libreswan·Package</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-package_libreswan_installed_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_allow_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">
17 ······<ocil:title>Verify·Group·Who·Owns·/etc/cron.allow·file</ocil:title>11 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_allow_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1"> 
23 ······<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_ocil:questionnaire:1"> 
29 ······<ocil:title>Disable·IPv6·Addressing·on·IPv6·Interfaces·by·Default</ocil:title> 
30 ······<ocil:actions>12 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>14 ······</ocil:actions>
33 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_acpi_custom_method_ocil:questionnaire:1"> 
35 ······<ocil:title>Do·not·allow·ACPI·methods·to·be·inserted/replaced·at·run·time</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_gshadow_ocil:questionnaire:1">
 17 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/gshadow</ocil:title>
36 ······<ocil:actions>18 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-kernel_config_acpi_custom_method_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_gshadow_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>20 ······</ocil:actions>
39 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chmod_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-selinux_confinement_of_daemons_ocil:questionnaire:1">
41 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chmod</ocil:title>23 ······<ocil:title>Ensure·No·Daemons·are·Unconfined·by·SELinux</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chmod_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-selinux_confinement_of_daemons_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">
47 ······<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>29 ······<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1"> 
53 ······<ocil:title>Disable·Kerberos·Authentication</ocil:title> 
54 ······<ocil:actions> 
55 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref> 
56 ······</ocil:actions> 
57 ····</ocil:questionnaire> 
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1">
59 ······<ocil:title>Make·the·auditd·Configuration·Immutable</ocil:title>35 ······<ocil:title>Verify·Permissions·on·crontab</ocil:title>
60 ······<ocil:actions>36 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>38 ······</ocil:actions>
63 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_init_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·init</ocil:title>41 ······<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title>
66 ······<ocil:actions>42 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_init_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>44 ······</ocil:actions>
69 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-package_xinetd_removed_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1">
71 ······<ocil:title>Uninstall·xinetd·Package</ocil:title>47 ······<ocil:title>Kernel·panic·timeout</ocil:title>
72 ······<ocil:actions>48 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-package_xinetd_removed_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_timeout_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>50 ······</ocil:actions>
75 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1">
77 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions</ocil:title>53 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
78 ······<ocil:actions>54 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>56 ······</ocil:actions>
81 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-package_libselinux_installed_ocil:questionnaire:1"> 
83 ······<ocil:title>Install·libselinux·Package</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-configure_user_data_backups_ocil:questionnaire:1">
 59 ······<ocil:title>Configure·Backups·of·User·Data</ocil:title>
84 ······<ocil:actions>60 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-package_libselinux_installed_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-configure_user_data_backups_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>62 ······</ocil:actions>
87 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1"> 
89 ······<ocil:title>Kernel·panic·timeout</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1">
 65 ······<ocil:title>Limit·the·Number·of·Concurrent·Login·Sessions·Allowed·Per·User</ocil:title>
90 ······<ocil:actions>66 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_timeout_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>68 ······</ocil:actions>
93 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-grub2_audit_argument_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">
95 ······<ocil:title>Enable·Auditing·for·Processes·Which·Start·Prior·to·the·Audit·Daemon</ocil:title>71 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>
96 ······<ocil:actions>72 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-grub2_audit_argument_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>74 ······</ocil:actions>
99 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-harden_ssh_client_crypto_policy_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_permissions_ocil:questionnaire:1">
101 ······<ocil:title>Harden·SSH·client·Crypto·Policy</ocil:title>77 ······<ocil:title>Verify·and·Correct·File·Permissions·with·RPM</ocil:title>
102 ······<ocil:actions>78 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-harden_ssh_client_crypto_policy_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-rpm_verify_permissions_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>80 ······</ocil:actions>
105 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1"> 
107 ······<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1">
 83 ······<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title>
108 ······<ocil:actions>84 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>86 ······</ocil:actions>
111 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">
113 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lsetxattr</ocil:title>89 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>
114 ······<ocil:actions>90 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>92 ······</ocil:actions>
117 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1"> 
119 ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1">
 95 ······<ocil:title>Ensure·the·Logon·Failure·Delay·is·Set·Correctly·in·login.defs</ocil:title>
120 ······<ocil:actions>96 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>98 ······</ocil:actions>
123 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-package_telnet_removed_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1">
Max diff block lines reached; 864047/875340 bytes (98.71%) of diff not shown.
1.02 MB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ds.xml
1.02 MB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-org.almalinux.alsa-9.xml.bz2"·xlink:href="https://security.almalinux.org/oval/org.almalinux.alsa-9.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-org.almalinux.alsa-9.xml.bz2"·xlink:href="https://security.almalinux.org/oval/org.almalinux.alsa-9.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:almalinux:almalinux:9">30 ······<cpe-dict:cpe-item·name="cpe:/o:almalinux:almalinux:9">
31 ········<cpe-dict:title·xml:lang="en-us">AlmaLinux·OS·9</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">AlmaLinux·OS·9</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml">oval:ssg-installed_OS_is_almalinux9:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml">oval:ssg-installed_OS_is_almalinux9:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALMALINUX-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALMALINUX-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·AlmaLinux·OS·9</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·AlmaLinux·OS·9</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·AlmaLinux·OS·9.·It·is·a·rendering·of42 configuration·settings·for·AlmaLinux·OS·9.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 131587, 15 lines modifiedOffset 131587, 15 lines modified
131587 ··············<xccdf-1.2:check-content-ref·href="ssg-almalinux9-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/>131587 ··············<xccdf-1.2:check-content-ref·href="ssg-almalinux9-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/>
131588 ············</xccdf-1.2:check>131588 ············</xccdf-1.2:check>
131589 ··········</xccdf-1.2:Rule>131589 ··········</xccdf-1.2:Rule>
131590 ········</xccdf-1.2:Group>131590 ········</xccdf-1.2:Group>
131591 ······</xccdf-1.2:Group>131591 ······</xccdf-1.2:Group>
131592 ····</xccdf-1.2:Benchmark>131592 ····</xccdf-1.2:Benchmark>
131593 ··</ds:component>131593 ··</ds:component>
131594 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-oval.xml"·timestamp="2025-02-28T20:08:00">131594 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-oval.xml"·timestamp="2025-03-01T22:08:00">
131595 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">131595 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
131596 ······<oval-def:generator>131596 ······<oval-def:generator>
131597 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>131597 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
131598 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>131598 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
131599 ········<oval:schema_version>5.11</oval:schema_version>131599 ········<oval:schema_version>5.11</oval:schema_version>
131600 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>131600 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
131601 ······</oval-def:generator>131601 ······</oval-def:generator>
Offset 154336, 6859 lines modifiedOffset 154336, 6812 lines modified
154336 ············</oval-def:arithmetic>154336 ············</oval-def:arithmetic>
154337 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>154337 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
154338 ··········</oval-def:arithmetic>154338 ··········</oval-def:arithmetic>
154339 ········</oval-def:local_variable>154339 ········</oval-def:local_variable>
154340 ······</oval-def:variables>154340 ······</oval-def:variables>
154341 ····</oval-def:oval_definitions>154341 ····</oval-def:oval_definitions>
154342 ··</ds:component>154342 ··</ds:component>
154343 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"·timestamp="2025-02-28T20:08:00">154343 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"·timestamp="2025-03-01T22:08:00">
154344 ····<ocil:ocil>154344 ····<ocil:ocil>
154345 ······<ocil:generator>154345 ······<ocil:generator>
154346 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>154346 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
154347 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>154347 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
154348 ········<ocil:schema_version>2.0</ocil:schema_version>154348 ········<ocil:schema_version>2.0</ocil:schema_version>
154349 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>154349 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
154350 ······</ocil:generator>154350 ······</ocil:generator>
154351 ······<ocil:questionnaires>154351 ······<ocil:questionnaires>
154352 ········<ocil:questionnaire·id="ocil:ssg-accounts_set_post_pw_existing_ocil:questionnaire:1">154352 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_ocil:questionnaire:1">
154353 ··········<ocil:title>Set·existing·passwords·a·period·of·inactivity·before·they·been·locked</ocil:title>154353 ··········<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title>
154354 ··········<ocil:actions>154354 ··········<ocil:actions>
154355 ············<ocil:test_action_ref>ocil:ssg-accounts_set_post_pw_existing_action:testaction:1</ocil:test_action_ref>154355 ············<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_action:testaction:1</ocil:test_action_ref>
154356 ··········</ocil:actions>154356 ··········</ocil:actions>
154357 ········</ocil:questionnaire>154357 ········</ocil:questionnaire>
154358 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">154358 ········<ocil:questionnaire·id="ocil:ssg-display_login_attempts_ocil:questionnaire:1">
154359 ··········<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>154359 ··········<ocil:title>Ensure·PAM·Displays·Last·Logon/Access·Notification</ocil:title>
154360 ··········<ocil:actions>154360 ··········<ocil:actions>
154361 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>154361 ············<ocil:test_action_ref>ocil:ssg-display_login_attempts_action:testaction:1</ocil:test_action_ref>
154362 ··········</ocil:actions>154362 ··········</ocil:actions>
154363 ········</ocil:questionnaire>154363 ········</ocil:questionnaire>
154364 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_system_shutdown_ocil:questionnaire:1">154364 ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_noexec_ocil:questionnaire:1">
154365 ··········<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>154365 ··········<ocil:title>Add·noexec·Option·to·/var/log</ocil:title>
154366 ··········<ocil:actions>154366 ··········<ocil:actions>
154367 ············<ocil:test_action_ref>ocil:ssg-audit_rules_system_shutdown_action:testaction:1</ocil:test_action_ref>154367 ············<ocil:test_action_ref>ocil:ssg-mount_option_var_log_noexec_action:testaction:1</ocil:test_action_ref>
154368 ··········</ocil:actions>154368 ··········</ocil:actions>
154369 ········</ocil:questionnaire>154369 ········</ocil:questionnaire>
154370 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_idle_delay_ocil:questionnaire:1">154370 ········<ocil:questionnaire·id="ocil:ssg-service_nfs_disabled_ocil:questionnaire:1">
154371 ··········<ocil:title>Set·GNOME3·Screensaver·Inactivity·Timeout</ocil:title>154371 ··········<ocil:title>Disable·Network·File·System·(nfs)</ocil:title>
154372 ··········<ocil:actions>154372 ··········<ocil:actions>
154373 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_idle_delay_action:testaction:1</ocil:test_action_ref>154373 ············<ocil:test_action_ref>ocil:ssg-service_nfs_disabled_action:testaction:1</ocil:test_action_ref>
154374 ··········</ocil:actions>154374 ··········</ocil:actions>
154375 ········</ocil:questionnaire>154375 ········</ocil:questionnaire>
154376 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">154376 ········<ocil:questionnaire·id="ocil:ssg-package_dnsmasq_removed_ocil:questionnaire:1">
154377 ··········<ocil:title>Verify·Owner·on·cron.weekly</ocil:title>154377 ··········<ocil:title>Uninstall·dnsmasq·Package</ocil:title>
154378 ··········<ocil:actions>154378 ··········<ocil:actions>
154379 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>154379 ············<ocil:test_action_ref>ocil:ssg-package_dnsmasq_removed_action:testaction:1</ocil:test_action_ref>
154380 ··········</ocil:actions>154380 ··········</ocil:actions>
154381 ········</ocil:questionnaire>154381 ········</ocil:questionnaire>
154382 ········<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1">154382 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">
154383 ··········<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title>154383 ··········<ocil:title>Verify·User·Who·Owns·Backup·gshadow·File</ocil:title>
154384 ··········<ocil:actions>154384 ··········<ocil:actions>
154385 ············<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>154385 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
154386 ··········</ocil:actions>154386 ··········</ocil:actions>
154387 ········</ocil:questionnaire>154387 ········</ocil:questionnaire>
154388 ········<ocil:questionnaire·id="ocil:ssg-has_nonlocal_mta_ocil:questionnaire:1">154388 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lchown_ocil:questionnaire:1">
154389 ··········<ocil:title>Ensure·Mail·Transfer·Agent·is·not·Listening·on·any·non-loopback·Address</ocil:title>154389 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lchown</ocil:title>
154390 ··········<ocil:actions>154390 ··········<ocil:actions>
154391 ············<ocil:test_action_ref>ocil:ssg-has_nonlocal_mta_action:testaction:1</ocil:test_action_ref>154391 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lchown_action:testaction:1</ocil:test_action_ref>
154392 ··········</ocil:actions>154392 ··········</ocil:actions>
154393 ········</ocil:questionnaire>154393 ········</ocil:questionnaire>
154394 ········<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_noexec_ocil:questionnaire:1">154394 ········<ocil:questionnaire·id="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1">
154395 ··········<ocil:title>Add·noexec·Option·to·/tmp</ocil:title>154395 ··········<ocil:title>Verify·Root·Has·A·Primary·GID·0</ocil:title>
154396 ··········<ocil:actions>154396 ··········<ocil:actions>
154397 ············<ocil:test_action_ref>ocil:ssg-mount_option_tmp_noexec_action:testaction:1</ocil:test_action_ref>154397 ············<ocil:test_action_ref>ocil:ssg-accounts_root_gid_zero_action:testaction:1</ocil:test_action_ref>
154398 ··········</ocil:actions>154398 ··········</ocil:actions>
154399 ········</ocil:questionnaire>154399 ········</ocil:questionnaire>
154400 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_query_ocil:questionnaire:1">154400 ········<ocil:questionnaire·id="ocil:ssg-package_aide_installed_ocil:questionnaire:1">
154401 ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading·-·query_module</ocil:title>154401 ··········<ocil:title>Install·AIDE</ocil:title>
154402 ··········<ocil:actions>154402 ··········<ocil:actions>
154403 ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_query_action:testaction:1</ocil:test_action_ref>154403 ············<ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref>
154404 ··········</ocil:actions>154404 ··········</ocil:actions>
154405 ········</ocil:questionnaire>154405 ········</ocil:questionnaire>
154406 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_config_ocil:questionnaire:1"> 
154407 ··········<ocil:title>Verify·Permissions·on·SSH·Server·config·file</ocil:title>154406 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_ocil:questionnaire:1">
 154407 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·unix_chkpwd</ocil:title>
154408 ··········<ocil:actions>154408 ··········<ocil:actions>
154409 ············<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_config_action:testaction:1</ocil:test_action_ref>154409 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_action:testaction:1</ocil:test_action_ref>
154410 ··········</ocil:actions>154410 ··········</ocil:actions>
154411 ········</ocil:questionnaire>154411 ········</ocil:questionnaire>
154412 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_crontab_ocil:questionnaire:1">154412 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1">
154413 ··········<ocil:title>Verify·Group·Who·Owns·Crontab</ocil:title>154413 ··········<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
154414 ··········<ocil:actions>154414 ··········<ocil:actions>
154415 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_crontab_action:testaction:1</ocil:test_action_ref>154415 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref>
154416 ··········</ocil:actions>154416 ··········</ocil:actions>
154417 ········</ocil:questionnaire>154417 ········</ocil:questionnaire>
154418 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1">154418 ········<ocil:questionnaire·id="ocil:ssg-set_firewalld_default_zone_ocil:questionnaire:1">
154419 ··········<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title>154419 ··········<ocil:title>Set·Default·firewalld·Zone·for·Incoming·Packets</ocil:title>
154420 ··········<ocil:actions>154420 ··········<ocil:actions>
154421 ············<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref>154421 ············<ocil:test_action_ref>ocil:ssg-set_firewalld_default_zone_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1060327/1072745 bytes (98.84%) of diff not shown.
1000 KB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ocil.xml
1000 KB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ocil.xml
Ordering differences only
    
Offset 3, 6850 lines modifiedOffset 3, 6803 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-accounts_set_post_pw_existing_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_ocil:questionnaire:1">
11 ······<ocil:title>Set·existing·passwords·a·period·of·inactivity·before·they·been·locked</ocil:title>11 ······<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-accounts_set_post_pw_existing_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-display_login_attempts_ocil:questionnaire:1">
17 ······<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>17 ······<ocil:title>Ensure·PAM·Displays·Last·Logon/Access·Notification</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-display_login_attempts_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_system_shutdown_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_noexec_ocil:questionnaire:1">
23 ······<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>23 ······<ocil:title>Add·noexec·Option·to·/var/log</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_system_shutdown_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_noexec_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_idle_delay_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-service_nfs_disabled_ocil:questionnaire:1">
29 ······<ocil:title>Set·GNOME3·Screensaver·Inactivity·Timeout</ocil:title>29 ······<ocil:title>Disable·Network·File·System·(nfs)</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_idle_delay_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-service_nfs_disabled_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-package_dnsmasq_removed_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Owner·on·cron.weekly</ocil:title>35 ······<ocil:title>Uninstall·dnsmasq·Package</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-package_dnsmasq_removed_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1"> 
41 ······<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">
 41 ······<ocil:title>Verify·User·Who·Owns·Backup·gshadow·File</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-has_nonlocal_mta_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lchown_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·Mail·Transfer·Agent·is·not·Listening·on·any·non-loopback·Address</ocil:title>47 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lchown</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-has_nonlocal_mta_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lchown_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_noexec_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1">
53 ······<ocil:title>Add·noexec·Option·to·/tmp</ocil:title>53 ······<ocil:title>Verify·Root·Has·A·Primary·GID·0</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_noexec_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-accounts_root_gid_zero_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_query_ocil:questionnaire:1"> 
59 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading·-·query_module</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-package_aide_installed_ocil:questionnaire:1">
 59 ······<ocil:title>Install·AIDE</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_query_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_config_ocil:questionnaire:1"> 
65 ······<ocil:title>Verify·Permissions·on·SSH·Server·config·file</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_ocil:questionnaire:1">
 65 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·unix_chkpwd</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_config_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_crontab_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Group·Who·Owns·Crontab</ocil:title>71 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_crontab_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-set_firewalld_default_zone_ocil:questionnaire:1">
77 ······<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title>77 ······<ocil:title>Set·Default·firewalld·Zone·for·Incoming·Packets</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-set_firewalld_default_zone_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1"> 
83 ······<ocil:title>Set·Password·Minimum·Age</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_config_ocil:questionnaire:1">
 83 ······<ocil:title>Verify·Permissions·on·SSH·Server·config·file</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_config_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-package_tftp-server_removed_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·that·/etc/at.deny·does·not·exist</ocil:title>89 ······<ocil:title>Uninstall·tftp-server·Package</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-package_tftp-server_removed_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_audit_installed_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmodat_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·the·audit·Subsystem·is·Installed</ocil:title>95 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmodat</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmodat_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chacl_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_maxstartups_ocil:questionnaire:1">
101 ······<ocil:title>Record·Any·Attempts·to·Run·chacl</ocil:title>101 ······<ocil:title>Ensure·SSH·MaxStartups·is·configured</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chacl_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sshd_set_maxstartups_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_maxrepeat_ocil:questionnaire:1"> 
107 ······<ocil:title>Set·Password·Maximum·Consecutive·Repeating·Characters</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_ocil:questionnaire:1">
 107 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open_by_handle_at</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_maxrepeat_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_user_cfg_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-libreswan_approved_tunnels_ocil:questionnaire:1">
113 ······<ocil:title>Verify·/boot/grub2/user.cfg·Group·Ownership</ocil:title>113 ······<ocil:title>Verify·Any·Configured·IPSec·Tunnel·Connections</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_user_cfg_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-libreswan_approved_tunnels_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_opasswd_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title>119 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/security/opasswd</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_opasswd_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_weekly_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1">
Max diff block lines reached; 1011491/1024143 bytes (98.76%) of diff not shown.
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ds.xml
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:23">28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:23">
29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·23</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·23</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml">oval:ssg-installed_OS_is_anolis23:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml">oval:ssg-installed_OS_is_anolis23:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-23"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-23"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·23</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·23</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Anolis·OS·23.·It·is·a·rendering·of40 configuration·settings·for·Anolis·OS·23.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 66305, 15 lines modifiedOffset 66305, 15 lines modified
66305 ··············<xccdf-1.2:check-content-ref·href="ssg-anolis23-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>66305 ··············<xccdf-1.2:check-content-ref·href="ssg-anolis23-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
66306 ············</xccdf-1.2:check>66306 ············</xccdf-1.2:check>
66307 ··········</xccdf-1.2:Rule>66307 ··········</xccdf-1.2:Rule>
66308 ········</xccdf-1.2:Group>66308 ········</xccdf-1.2:Group>
66309 ······</xccdf-1.2:Group>66309 ······</xccdf-1.2:Group>
66310 ····</xccdf-1.2:Benchmark>66310 ····</xccdf-1.2:Benchmark>
66311 ··</ds:component>66311 ··</ds:component>
66312 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-oval.xml"·timestamp="2025-02-28T20:08:00">66312 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-oval.xml"·timestamp="2025-03-01T22:08:00">
66313 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">66313 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
66314 ······<oval-def:generator>66314 ······<oval-def:generator>
66315 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>66315 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
66316 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>66316 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
66317 ········<oval:schema_version>5.11</oval:schema_version>66317 ········<oval:schema_version>5.11</oval:schema_version>
66318 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>66318 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
66319 ······</oval-def:generator>66319 ······</oval-def:generator>
Offset 90165, 7331 lines modifiedOffset 90165, 7379 lines modified
90165 ············</oval-def:arithmetic>90165 ············</oval-def:arithmetic>
90166 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>90166 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
90167 ··········</oval-def:arithmetic>90167 ··········</oval-def:arithmetic>
90168 ········</oval-def:local_variable>90168 ········</oval-def:local_variable>
90169 ······</oval-def:variables>90169 ······</oval-def:variables>
90170 ····</oval-def:oval_definitions>90170 ····</oval-def:oval_definitions>
90171 ··</ds:component>90171 ··</ds:component>
90172 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-ocil.xml"·timestamp="2025-02-28T20:08:00">90172 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-ocil.xml"·timestamp="2025-03-01T22:08:00">
90173 ····<ocil:ocil>90173 ····<ocil:ocil>
90174 ······<ocil:generator>90174 ······<ocil:generator>
90175 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>90175 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
90176 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>90176 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
90177 ········<ocil:schema_version>2.0</ocil:schema_version>90177 ········<ocil:schema_version>2.0</ocil:schema_version>
90178 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>90178 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
90179 ······</ocil:generator>90179 ······</ocil:generator>
90180 ······<ocil:questionnaires>90180 ······<ocil:questionnaires>
90181 ········<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1"> 
90182 ··········<ocil:title>Verify·iptables·Enabled</ocil:title> 
90183 ··········<ocil:actions> 
90184 ············<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref> 
90185 ··········</ocil:actions> 
90186 ········</ocil:questionnaire> 
90187 ········<ocil:questionnaire·id="ocil:ssg-package_libreswan_installed_ocil:questionnaire:1">90181 ········<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">
90188 ··········<ocil:title>Install·libreswan·Package</ocil:title>90182 ··········<ocil:title>Install·the·cron·service</ocil:title>
90189 ··········<ocil:actions>90183 ··········<ocil:actions>
90190 ············<ocil:test_action_ref>ocil:ssg-package_libreswan_installed_action:testaction:1</ocil:test_action_ref>90184 ············<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>
90191 ··········</ocil:actions>90185 ··········</ocil:actions>
90192 ········</ocil:questionnaire>90186 ········</ocil:questionnaire>
90193 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1">90187 ········<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_poweroff_ocil:questionnaire:1">
90194 ··········<ocil:title>Verify·Permissions·on·group·File</ocil:title>90188 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·poweroff</ocil:title>
90195 ··········<ocil:actions>90189 ··········<ocil:actions>
90196 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_group_action:testaction:1</ocil:test_action_ref>90190 ············<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_poweroff_action:testaction:1</ocil:test_action_ref>
90197 ··········</ocil:actions>90191 ··········</ocil:actions>
90198 ········</ocil:questionnaire>90192 ········</ocil:questionnaire>
90199 ········<ocil:questionnaire·id="ocil:ssg-ensure_redhat_gpgkey_installed_ocil:questionnaire:1">90193 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_kexec_ocil:questionnaire:1">
90200 ··········<ocil:title>Ensure·Red·Hat·GPG·Key·Installed</ocil:title>90194 ··········<ocil:title>Disable·kexec·system·call</ocil:title>
90201 ··········<ocil:actions>90195 ··········<ocil:actions>
90202 ············<ocil:test_action_ref>ocil:ssg-ensure_redhat_gpgkey_installed_action:testaction:1</ocil:test_action_ref>90196 ············<ocil:test_action_ref>ocil:ssg-kernel_config_kexec_action:testaction:1</ocil:test_action_ref>
90203 ··········</ocil:actions>90197 ··········</ocil:actions>
90204 ········</ocil:questionnaire>90198 ········</ocil:questionnaire>
90205 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_sshd_config_ocil:questionnaire:1">90199 ········<ocil:questionnaire·id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1">
90206 ··········<ocil:title>Verify·Group·Who·Owns·SSH·Server·config·file</ocil:title>90200 ··········<ocil:title>Limit·the·Number·of·Concurrent·Login·Sessions·Allowed·Per·User</ocil:title>
90207 ··········<ocil:actions>90201 ··········<ocil:actions>
90208 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_sshd_config_action:testaction:1</ocil:test_action_ref>90202 ············<ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>
90209 ··········</ocil:actions>90203 ··········</ocil:actions>
90210 ········</ocil:questionnaire>90204 ········</ocil:questionnaire>
90211 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1">90205 ········<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">
90212 ··········<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title>90206 ··········<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>
90213 ··········<ocil:actions>90207 ··········<ocil:actions>
90214 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>90208 ············<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>
90215 ··········</ocil:actions>90209 ··········</ocil:actions>
90216 ········</ocil:questionnaire>90210 ········</ocil:questionnaire>
90217 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1">90211 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1">
90218 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title>90212 ··········<ocil:title>Set·SSH·Client·Alive·Count·Max·to·zero</ocil:title>
90219 ··········<ocil:actions>90213 ··········<ocil:actions>
90220 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref>90214 ············<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_0_action:testaction:1</ocil:test_action_ref>
90221 ··········</ocil:actions>90215 ··········</ocil:actions>
90222 ········</ocil:questionnaire>90216 ········</ocil:questionnaire>
90223 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1"> 
90224 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·creat</ocil:title>90217 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
 90218 ··········<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
90225 ··········<ocil:actions>90219 ··········<ocil:actions>
90226 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref>90220 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
90227 ··········</ocil:actions>90221 ··········</ocil:actions>
90228 ········</ocil:questionnaire>90222 ········</ocil:questionnaire>
90229 ········<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">90223 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_d_ocil:questionnaire:1">
90230 ··········<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>90224 ··········<ocil:title>Verify·Owner·on·cron.d</ocil:title>
90231 ··········<ocil:actions>90225 ··········<ocil:actions>
90232 ············<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>90226 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_d_action:testaction:1</ocil:test_action_ref>
90233 ··········</ocil:actions>90227 ··········</ocil:actions>
90234 ········</ocil:questionnaire>90228 ········</ocil:questionnaire>
90235 ········<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1">90229 ········<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1">
90236 ··········<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title>90230 ··········<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title>
90237 ··········<ocil:actions>90231 ··········<ocil:actions>
90238 ············<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref>90232 ············<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref>
90239 ··········</ocil:actions>90233 ··········</ocil:actions>
90240 ········</ocil:questionnaire>90234 ········</ocil:questionnaire>
90241 ········<ocil:questionnaire·id="ocil:ssg-no_rsh_trust_files_ocil:questionnaire:1">90235 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1">
90242 ··········<ocil:title>Remove·Rsh·Trust·Files</ocil:title>90236 ··········<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>
90243 ··········<ocil:actions>90237 ··········<ocil:actions>
90244 ············<ocil:test_action_ref>ocil:ssg-no_rsh_trust_files_action:testaction:1</ocil:test_action_ref>90238 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>
90245 ··········</ocil:actions>90239 ··········</ocil:actions>
90246 ········</ocil:questionnaire>90240 ········</ocil:questionnaire>
90247 ········<ocil:questionnaire·id="ocil:ssg-dir_ownership_library_dirs_ocil:questionnaire:1">90241 ········<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_ocil:questionnaire:1">
90248 ··········<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Ownership</ocil:title>90242 ··········<ocil:title>Prevent·Login·to·Accounts·With·Empty·Password</ocil:title>
90249 ··········<ocil:actions>90243 ··········<ocil:actions>
90250 ············<ocil:test_action_ref>ocil:ssg-dir_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>90244 ············<ocil:test_action_ref>ocil:ssg-no_empty_passwords_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1047613/1059524 bytes (98.88%) of diff not shown.
988 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ocil.xml
988 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ocil.xml
Ordering differences only
    
Offset 3, 7322 lines modifiedOffset 3, 7370 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1"> 
11 ······<ocil:title>Verify·iptables·Enabled</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-package_libreswan_installed_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">
17 ······<ocil:title>Install·libreswan·Package</ocil:title>11 ······<ocil:title>Install·the·cron·service</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_libreswan_installed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_poweroff_ocil:questionnaire:1">
23 ······<ocil:title>Verify·Permissions·on·group·File</ocil:title>17 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·poweroff</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_group_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_poweroff_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-ensure_redhat_gpgkey_installed_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_kexec_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·Red·Hat·GPG·Key·Installed</ocil:title>23 ······<ocil:title>Disable·kexec·system·call</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-ensure_redhat_gpgkey_installed_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_kexec_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_sshd_config_ocil:questionnaire:1"> 
35 ······<ocil:title>Verify·Group·Who·Owns·SSH·Server·config·file</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1">
 29 ······<ocil:title>Limit·the·Number·of·Concurrent·Login·Sessions·Allowed·Per·User</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_sshd_config_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title>35 ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1"> 
47 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1">
 41 ······<ocil:title>Set·SSH·Client·Alive·Count·Max·to·zero</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_0_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1"> 
53 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·creat</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
 47 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_d_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>53 ······<ocil:title>Verify·Owner·on·cron.d</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_d_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1">
65 ······<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title>59 ······<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-no_rsh_trust_files_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1">
71 ······<ocil:title>Remove·Rsh·Trust·Files</ocil:title>65 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-no_rsh_trust_files_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_library_dirs_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_ocil:questionnaire:1">
77 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Ownership</ocil:title>71 ······<ocil:title>Prevent·Login·to·Accounts·With·Empty·Password</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-no_empty_passwords_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_shutdown_ocil:questionnaire:1"> 
83 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·shutdown</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1">
 77 ······<ocil:title>Remove·the·kernel·mapping·in·user·mode</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_shutdown_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_table_isolation_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_notifiers_ocil:questionnaire:1"> 
89 ······<ocil:title>Enable·checks·on·notifier·call·chains</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_at_allow_ocil:questionnaire:1">
 83 ······<ocil:title>Verify·Group·Who·Owns·/etc/at.allow·file</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_notifiers_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_at_allow_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1">
95 ······<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title>89 ······<ocil:title>Prefer·to·use·a·64-bit·Operating·System·when·supported</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_ocil:questionnaire:1"> 
101 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1">
 95 ······<ocil:title>Disable·the·Automounter</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1"> 
107 ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-service_syslogng_enabled_ocil:questionnaire:1">
 101 ······<ocil:title>Enable·syslog-ng·Service</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-service_syslogng_enabled_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">
113 ······<ocil:title>Make·the·auditd·Configuration·Immutable</ocil:title>107 ······<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_passwd_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-configure_openssl_crypto_policy_ocil:questionnaire:1">
119 ······<ocil:title>Verify·Group·Who·Owns·Backup·passwd·File</ocil:title>113 ······<ocil:title>Configure·OpenSSL·library·to·use·System·Crypto·Policy</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-configure_openssl_crypto_policy_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
Max diff block lines reached; 999635/1011638 bytes (98.81%) of diff not shown.
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds.xml
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:8">28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:8">
29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·8</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·8</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml">oval:ssg-installed_OS_is_anolis8:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml">oval:ssg-installed_OS_is_anolis8:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·8</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·8</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Anolis·OS·8.·It·is·a·rendering·of40 configuration·settings·for·Anolis·OS·8.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 66305, 15 lines modifiedOffset 66305, 15 lines modified
66305 ··············<xccdf-1.2:check-content-ref·href="ssg-anolis8-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>66305 ··············<xccdf-1.2:check-content-ref·href="ssg-anolis8-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
66306 ············</xccdf-1.2:check>66306 ············</xccdf-1.2:check>
66307 ··········</xccdf-1.2:Rule>66307 ··········</xccdf-1.2:Rule>
66308 ········</xccdf-1.2:Group>66308 ········</xccdf-1.2:Group>
66309 ······</xccdf-1.2:Group>66309 ······</xccdf-1.2:Group>
66310 ····</xccdf-1.2:Benchmark>66310 ····</xccdf-1.2:Benchmark>
66311 ··</ds:component>66311 ··</ds:component>
66312 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-oval.xml"·timestamp="2025-02-28T20:08:00">66312 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-oval.xml"·timestamp="2025-03-01T22:08:00">
66313 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">66313 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
66314 ······<oval-def:generator>66314 ······<oval-def:generator>
66315 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>66315 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
66316 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>66316 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
66317 ········<oval:schema_version>5.11</oval:schema_version>66317 ········<oval:schema_version>5.11</oval:schema_version>
66318 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>66318 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
66319 ······</oval-def:generator>66319 ······</oval-def:generator>
Offset 90165, 6672 lines modifiedOffset 90165, 6771 lines modified
90165 ············</oval-def:arithmetic>90165 ············</oval-def:arithmetic>
90166 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>90166 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
90167 ··········</oval-def:arithmetic>90167 ··········</oval-def:arithmetic>
90168 ········</oval-def:local_variable>90168 ········</oval-def:local_variable>
90169 ······</oval-def:variables>90169 ······</oval-def:variables>
90170 ····</oval-def:oval_definitions>90170 ····</oval-def:oval_definitions>
90171 ··</ds:component>90171 ··</ds:component>
90172 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-ocil.xml"·timestamp="2025-02-28T20:08:00">90172 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-ocil.xml"·timestamp="2025-03-01T22:08:00">
90173 ····<ocil:ocil>90173 ····<ocil:ocil>
90174 ······<ocil:generator>90174 ······<ocil:generator>
90175 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>90175 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
90176 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>90176 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
90177 ········<ocil:schema_version>2.0</ocil:schema_version>90177 ········<ocil:schema_version>2.0</ocil:schema_version>
90178 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>90178 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
90179 ······</ocil:generator>90179 ······</ocil:generator>
90180 ······<ocil:questionnaires>90180 ······<ocil:questionnaires>
90181 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_ocil:questionnaire:1"> 
90182 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv6·Interfaces</ocil:title> 
90183 ··········<ocil:actions> 
90184 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref> 
90185 ··········</ocil:actions> 
90186 ········</ocil:questionnaire> 
90187 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1"> 
90188 ··········<ocil:title>Disable·kernel·debugfs</ocil:title> 
90189 ··········<ocil:actions> 
90190 ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref> 
90191 ··········</ocil:actions> 
90192 ········</ocil:questionnaire> 
90193 ········<ocil:questionnaire·id="ocil:ssg-service_rdisc_disabled_ocil:questionnaire:1">90181 ········<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">
90194 ··········<ocil:title>Disable·Network·Router·Discovery·Daemon·(rdisc)</ocil:title>90182 ··········<ocil:title>Enable·auditd·Service</ocil:title>
90195 ··········<ocil:actions>90183 ··········<ocil:actions>
90196 ············<ocil:test_action_ref>ocil:ssg-service_rdisc_disabled_action:testaction:1</ocil:test_action_ref>90184 ············<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>
90197 ··········</ocil:actions>90185 ··········</ocil:actions>
90198 ········</ocil:questionnaire>90186 ········</ocil:questionnaire>
90199 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1">90187 ········<ocil:questionnaire·id="ocil:ssg-coredump_disable_backtraces_ocil:questionnaire:1">
90200 ··········<ocil:title>Kernel·panic·timeout</ocil:title>90188 ··········<ocil:title>Disable·core·dump·backtraces</ocil:title>
90201 ··········<ocil:actions>90189 ··········<ocil:actions>
90202 ············<ocil:test_action_ref>ocil:ssg-kernel_config_panic_timeout_action:testaction:1</ocil:test_action_ref>90190 ············<ocil:test_action_ref>ocil:ssg-coredump_disable_backtraces_action:testaction:1</ocil:test_action_ref>
90203 ··········</ocil:actions>90191 ··········</ocil:actions>
90204 ········</ocil:questionnaire>90192 ········</ocil:questionnaire>
90205 ········<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">90193 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">
90206 ··········<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>90194 ··········<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title>
90207 ··········<ocil:actions>90195 ··········<ocil:actions>
90208 ············<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>90196 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref>
90209 ··········</ocil:actions>90197 ··········</ocil:actions>
90210 ········</ocil:questionnaire>90198 ········</ocil:questionnaire>
90211 ········<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">90199 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_issue_ocil:questionnaire:1">
90212 ··········<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>90200 ··········<ocil:title>Verify·permissions·on·System·Login·Banner</ocil:title>
90213 ··········<ocil:actions>90201 ··········<ocil:actions>
90214 ············<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>90202 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_action:testaction:1</ocil:test_action_ref>
90215 ··········</ocil:actions>90203 ··········</ocil:actions>
90216 ········</ocil:questionnaire>90204 ········</ocil:questionnaire>
90217 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1"> 
90218 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>90205 ········<ocil:questionnaire·id="ocil:ssg-sshd_use_priv_separation_ocil:questionnaire:1">
 90206 ··········<ocil:title>Enable·Use·of·Privilege·Separation</ocil:title>
90219 ··········<ocil:actions>90207 ··········<ocil:actions>
90220 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>90208 ············<ocil:test_action_ref>ocil:ssg-sshd_use_priv_separation_action:testaction:1</ocil:test_action_ref>
90221 ··········</ocil:actions>90209 ··········</ocil:actions>
90222 ········</ocil:questionnaire>90210 ········</ocil:questionnaire>
90223 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_ocil:questionnaire:1"> 
90224 ··········<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·for·All·IPv4·Interfaces</ocil:title>90211 ········<ocil:questionnaire·id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1">
 90212 ··········<ocil:title>Ensure·the·Logon·Failure·Delay·is·Set·Correctly·in·login.defs</ocil:title>
90225 ··········<ocil:actions>90213 ··········<ocil:actions>
90226 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_action:testaction:1</ocil:test_action_ref>90214 ············<ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>
90227 ··········</ocil:actions>90215 ··········</ocil:actions>
90228 ········</ocil:questionnaire>90216 ········</ocil:questionnaire>
90229 ········<ocil:questionnaire·id="ocil:ssg-account_disable_post_pw_expiration_ocil:questionnaire:1">90217 ········<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">
90230 ··········<ocil:title>Set·Account·Expiration·Following·Inactivity</ocil:title>90218 ··········<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>
90231 ··········<ocil:actions>90219 ··········<ocil:actions>
90232 ············<ocil:test_action_ref>ocil:ssg-account_disable_post_pw_expiration_action:testaction:1</ocil:test_action_ref>90220 ············<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>
90233 ··········</ocil:actions>90221 ··········</ocil:actions>
90234 ········</ocil:questionnaire>90222 ········</ocil:questionnaire>
90235 ········<ocil:questionnaire·id="ocil:ssg-service_named_disabled_ocil:questionnaire:1"> 
90236 ··········<ocil:title>Disable·named·Service</ocil:title>90223 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1">
 90224 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>
90237 ··········<ocil:actions>90225 ··········<ocil:actions>
90238 ············<ocil:test_action_ref>ocil:ssg-service_named_disabled_action:testaction:1</ocil:test_action_ref>90226 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>
90239 ··········</ocil:actions>90227 ··········</ocil:actions>
90240 ········</ocil:questionnaire>90228 ········</ocil:questionnaire>
90241 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_ocil:questionnaire:1"> 
90242 ··········<ocil:title>Prevent·Routing·External·Traffic·to·Local·Loopback·on·All·IPv4·Interfaces</ocil:title>90229 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">
 90230 ··········<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>
90243 ··········<ocil:actions>90231 ··········<ocil:actions>
90244 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_action:testaction:1</ocil:test_action_ref>90232 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
90245 ··········</ocil:actions>90233 ··········</ocil:actions>
90246 ········</ocil:questionnaire>90234 ········</ocil:questionnaire>
90247 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_ocil:questionnaire:1">90235 ········<ocil:questionnaire·id="ocil:ssg-file_owner_grub2_cfg_ocil:questionnaire:1">
Max diff block lines reached; 1044585/1056143 bytes (98.91%) of diff not shown.
985 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ocil.xml
985 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ocil.xml
Ordering differences only
    
Offset 3, 6663 lines modifiedOffset 3, 6762 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_ocil:questionnaire:1"> 
11 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv6·Interfaces</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1"> 
17 ······<ocil:title>Disable·kernel·debugfs</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-service_rdisc_disabled_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">
23 ······<ocil:title>Disable·Network·Router·Discovery·Daemon·(rdisc)</ocil:title>11 ······<ocil:title>Enable·auditd·Service</ocil:title>
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-service_rdisc_disabled_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-coredump_disable_backtraces_ocil:questionnaire:1">
29 ······<ocil:title>Kernel·panic·timeout</ocil:title>17 ······<ocil:title>Disable·core·dump·backtraces</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_timeout_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-coredump_disable_backtraces_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">
35 ······<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>23 ······<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_issue_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>29 ······<ocil:title>Verify·permissions·on·System·Login·Banner</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1"> 
47 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_priv_separation_ocil:questionnaire:1">
 35 ······<ocil:title>Enable·Use·of·Privilege·Separation</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_use_priv_separation_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_ocil:questionnaire:1"> 
53 ······<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·for·All·IPv4·Interfaces</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1">
 41 ······<ocil:title>Ensure·the·Logon·Failure·Delay·is·Set·Correctly·in·login.defs</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-account_disable_post_pw_expiration_ocil:questionnaire:1"> 
59 ······<ocil:title>Set·Account·Expiration·Following·Inactivity</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">
 47 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-account_disable_post_pw_expiration_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-service_named_disabled_ocil:questionnaire:1"> 
65 ······<ocil:title>Disable·named·Service</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1">
 53 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-service_named_disabled_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_ocil:questionnaire:1"> 
71 ······<ocil:title>Prevent·Routing·External·Traffic·to·Local·Loopback·on·All·IPv4·Interfaces</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">
 59 ······<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_grub2_cfg_ocil:questionnaire:1">
77 ······<ocil:title>Enable·Kernel·Parameter·to·Log·Martian·Packets·on·all·IPv4·Interfaces</ocil:title>65 ······<ocil:title>Verify·/boot/grub2/grub.cfg·User·Ownership</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_owner_grub2_cfg_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1"> 
83 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1">
 71 ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">
89 ······<ocil:title>System·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>77 ······<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-service_nfs_disabled_ocil:questionnaire:1"> 
95 ······<ocil:title>Disable·Network·File·System·(nfs)</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_max_life_existing_ocil:questionnaire:1">
 83 ······<ocil:title>Set·Existing·Passwords·Maximum·Age</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-service_nfs_disabled_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_existing_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_hourly_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_group_ocil:questionnaire:1">
101 ······<ocil:title>Verify·Owner·on·cron.hourly</ocil:title>89 ······<ocil:title>Verify·User·Who·Owns·Backup·group·File</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_hourly_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-service_httpd_disabled_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1">
107 ······<ocil:title>Disable·httpd·Service</ocil:title>95 ······<ocil:title>Do·Not·Allow·SSH·Environment·Options</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-service_httpd_disabled_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_motd_ocil:questionnaire:1">
113 ······<ocil:title>Enable·Yama·support</ocil:title>101 ······<ocil:title>Verify·permissions·on·Message·of·the·Day·Banner</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_yama_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_motd_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·all·users·last·password·change·date·is·in·the·past</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_ocil:questionnaire:1">
 107 ······<ocil:title>Verify·User·Who·Owns·/var/log·Directory</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 996512/1008357 bytes (98.83%) of diff not shown.
3.42 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds.xml
3.42 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>
Offset 75, 15 lines modifiedOffset 75, 15 lines modified
75 ······</cpe-dict:cpe-item>75 ······</cpe-dict:cpe-item>
76 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:8">76 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:8">
77 ········<cpe-dict:title·xml:lang="en-us">CentOS·8</cpe-dict:title>77 ········<cpe-dict:title·xml:lang="en-us">CentOS·8</cpe-dict:title>
78 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_centos8:def:1</cpe-dict:check>78 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_centos8:def:1</cpe-dict:check>
79 ······</cpe-dict:cpe-item>79 ······</cpe-dict:cpe-item>
80 ····</cpe-dict:cpe-list>80 ····</cpe-dict:cpe-list>
81 ··</ds:component>81 ··</ds:component>
82 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-02-28T20:08:00">82 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
83 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">83 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
84 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>84 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
85 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>85 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>
86 ······<xccdf-1.2:description>86 ······<xccdf-1.2:description>
87 ········This·guide·presents·a·catalog·of·security-relevant87 ········This·guide·presents·a·catalog·of·security-relevant
88 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of88 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of
89 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)89 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 488, 25 lines modifiedOffset 488, 25 lines modified
488 ··········</cpe-lang:logical-test>488 ··········</cpe-lang:logical-test>
489 ········</cpe-lang:platform>489 ········</cpe-lang:platform>
490 ········<cpe-lang:platform·id="package_bash">490 ········<cpe-lang:platform·id="package_bash">
491 ··········<cpe-lang:logical-test·operator="AND"·negate="false">491 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
492 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>492 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
493 ··········</cpe-lang:logical-test>493 ··········</cpe-lang:logical-test>
494 ········</cpe-lang:platform>494 ········</cpe-lang:platform>
495 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
496 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
497 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
498 ··········</cpe-lang:logical-test> 
499 ········</cpe-lang:platform> 
500 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">495 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
501 ··········<cpe-lang:logical-test·operator="AND"·negate="false">496 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
502 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>497 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
503 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>498 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
504 ··········</cpe-lang:logical-test>499 ··········</cpe-lang:logical-test>
505 ········</cpe-lang:platform>500 ········</cpe-lang:platform>
 501 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 502 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 503 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 504 ··········</cpe-lang:logical-test>
 505 ········</cpe-lang:platform>
506 ········<cpe-lang:platform·id="not_s390x_arch">506 ········<cpe-lang:platform·id="not_s390x_arch">
507 ··········<cpe-lang:logical-test·operator="AND"·negate="false">507 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
508 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>508 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
509 ··········</cpe-lang:logical-test>509 ··········</cpe-lang:logical-test>
510 ········</cpe-lang:platform>510 ········</cpe-lang:platform>
511 ········<cpe-lang:platform·id="package_tmux">511 ········<cpe-lang:platform·id="package_tmux">
512 ··········<cpe-lang:logical-test·operator="AND"·negate="false">512 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 312766, 15 lines modifiedOffset 312766, 15 lines modified
312766 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>312766 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
312767 ············</xccdf-1.2:check>312767 ············</xccdf-1.2:check>
312768 ··········</xccdf-1.2:Rule>312768 ··········</xccdf-1.2:Rule>
312769 ········</xccdf-1.2:Group>312769 ········</xccdf-1.2:Group>
312770 ······</xccdf-1.2:Group>312770 ······</xccdf-1.2:Group>
312771 ····</xccdf-1.2:Benchmark>312771 ····</xccdf-1.2:Benchmark>
312772 ··</ds:component>312772 ··</ds:component>
312773 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-02-28T20:08:00">312773 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-03-01T22:08:00">
312774 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">312774 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
312775 ······<oval-def:generator>312775 ······<oval-def:generator>
312776 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>312776 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
312777 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>312777 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
312778 ········<oval:schema_version>5.11</oval:schema_version>312778 ········<oval:schema_version>5.11</oval:schema_version>
312779 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>312779 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
312780 ······</oval-def:generator>312780 ······</oval-def:generator>
Offset 379152, 12335 lines modifiedOffset 379152, 12335 lines modified
379152 ············</oval-def:arithmetic>379152 ············</oval-def:arithmetic>
379153 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>379153 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>
379154 ··········</oval-def:arithmetic>379154 ··········</oval-def:arithmetic>
379155 ········</oval-def:local_variable>379155 ········</oval-def:local_variable>
379156 ······</oval-def:variables>379156 ······</oval-def:variables>
379157 ····</oval-def:oval_definitions>379157 ····</oval-def:oval_definitions>
379158 ··</ds:component>379158 ··</ds:component>
379159 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-02-28T20:08:00">379159 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-03-01T22:08:00">
379160 ····<ocil:ocil>379160 ····<ocil:ocil>
379161 ······<ocil:generator>379161 ······<ocil:generator>
379162 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>379162 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
379163 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>379163 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
379164 ········<ocil:schema_version>2.0</ocil:schema_version>379164 ········<ocil:schema_version>2.0</ocil:schema_version>
379165 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>379165 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
379166 ······</ocil:generator>379166 ······</ocil:generator>
379167 ······<ocil:questionnaires>379167 ······<ocil:questionnaires>
379168 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">379168 ········<ocil:questionnaire·id="ocil:ssg-nfs_no_anonymous_ocil:questionnaire:1">
379169 ··········<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>379169 ··········<ocil:title>Specify·UID·and·GID·for·Anonymous·NFS·Connections</ocil:title>
379170 ··········<ocil:actions>379170 ··········<ocil:actions>
379171 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>379171 ············<ocil:test_action_ref>ocil:ssg-nfs_no_anonymous_action:testaction:1</ocil:test_action_ref>
379172 ··········</ocil:actions>379172 ··········</ocil:actions>
379173 ········</ocil:questionnaire>379173 ········</ocil:questionnaire>
379174 ········<ocil:questionnaire·id="ocil:ssg-package_tftp_removed_ocil:questionnaire:1">379174 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1">
379175 ··········<ocil:title>Remove·tftp·Daemon</ocil:title>379175 ··········<ocil:title>Verify·Permissions·on·/etc/at.allow·file</ocil:title>
379176 ··········<ocil:actions>379176 ··········<ocil:actions>
379177 ············<ocil:test_action_ref>ocil:ssg-package_tftp_removed_action:testaction:1</ocil:test_action_ref>379177 ············<ocil:test_action_ref>ocil:ssg-file_permissions_at_allow_action:testaction:1</ocil:test_action_ref>
379178 ··········</ocil:actions>379178 ··········</ocil:actions>
379179 ········</ocil:questionnaire>379179 ········</ocil:questionnaire>
379180 ········<ocil:questionnaire·id="ocil:ssg-ldap_client_start_tls_ocil:questionnaire:1">379180 ········<ocil:questionnaire·id="ocil:ssg-audit_ospp_general_ocil:questionnaire:1">
379181 ··········<ocil:title>Configure·LDAP·Client·to·Use·TLS·For·All·Transactions</ocil:title>379181 ··········<ocil:title>Perform·general·configuration·of·Audit·for·OSPP</ocil:title>
379182 ··········<ocil:actions>379182 ··········<ocil:actions>
379183 ············<ocil:test_action_ref>ocil:ssg-ldap_client_start_tls_action:testaction:1</ocil:test_action_ref>379183 ············<ocil:test_action_ref>ocil:ssg-audit_ospp_general_action:testaction:1</ocil:test_action_ref>
379184 ··········</ocil:actions>379184 ··········</ocil:actions>
379185 ········</ocil:questionnaire>379185 ········</ocil:questionnaire>
379186 ········<ocil:questionnaire·id="ocil:ssg-service_sshd_enabled_ocil:questionnaire:1">379186 ········<ocil:questionnaire·id="ocil:ssg-sebool_daemons_dump_core_ocil:questionnaire:1">
379187 ··········<ocil:title>Enable·the·OpenSSH·Service</ocil:title>379187 ··········<ocil:title>Disable·the·daemons_dump_core·SELinux·Boolean</ocil:title>
379188 ··········<ocil:actions>379188 ··········<ocil:actions>
379189 ············<ocil:test_action_ref>ocil:ssg-service_sshd_enabled_action:testaction:1</ocil:test_action_ref>379189 ············<ocil:test_action_ref>ocil:ssg-sebool_daemons_dump_core_action:testaction:1</ocil:test_action_ref>
379190 ··········</ocil:actions>379190 ··········</ocil:actions>
379191 ········</ocil:questionnaire>379191 ········</ocil:questionnaire>
379192 ········<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_rng_ocil:questionnaire:1">379192 ········<ocil:questionnaire·id="ocil:ssg-sebool_domain_kernel_load_modules_ocil:questionnaire:1">
379193 ··········<ocil:title>SSH·server·uses·strong·entropy·to·seed</ocil:title>379193 ··········<ocil:title>Disable·the·domain_kernel_load_modules·SELinux·Boolean</ocil:title>
379194 ··········<ocil:actions>379194 ··········<ocil:actions>
379195 ············<ocil:test_action_ref>ocil:ssg-sshd_use_strong_rng_action:testaction:1</ocil:test_action_ref>379195 ············<ocil:test_action_ref>ocil:ssg-sebool_domain_kernel_load_modules_action:testaction:1</ocil:test_action_ref>
379196 ··········</ocil:actions>379196 ··········</ocil:actions>
379197 ········</ocil:questionnaire>379197 ········</ocil:questionnaire>
379198 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_at_allow_ocil:questionnaire:1">379198 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_rds_disabled_ocil:questionnaire:1">
379199 ··········<ocil:title>Verify·Group·Who·Owns·/etc/at.allow·file</ocil:title>379199 ··········<ocil:title>Disable·RDS·Support</ocil:title>
Max diff block lines reached; 3576158/3586777 bytes (99.70%) of diff not shown.
2.3 KB
./usr/share/xml/scap/ssg/content/ssg-centos8-xccdf.xml
2.19 KB
./usr/share/xml/scap/ssg/content/ssg-centos8-xccdf.xml
Ordering differences only
    
Offset 407, 25 lines modifiedOffset 407, 25 lines modified
407 ······</cpe-lang:logical-test>407 ······</cpe-lang:logical-test>
408 ····</cpe-lang:platform>408 ····</cpe-lang:platform>
409 ····<cpe-lang:platform·id="package_bash">409 ····<cpe-lang:platform·id="package_bash">
410 ······<cpe-lang:logical-test·operator="AND"·negate="false">410 ······<cpe-lang:logical-test·operator="AND"·negate="false">
411 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>411 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
412 ······</cpe-lang:logical-test>412 ······</cpe-lang:logical-test>
413 ····</cpe-lang:platform>413 ····</cpe-lang:platform>
414 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
415 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
416 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
417 ······</cpe-lang:logical-test> 
418 ····</cpe-lang:platform> 
419 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">414 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
420 ······<cpe-lang:logical-test·operator="AND"·negate="false">415 ······<cpe-lang:logical-test·operator="AND"·negate="false">
421 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>416 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
422 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>417 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
423 ······</cpe-lang:logical-test>418 ······</cpe-lang:logical-test>
424 ····</cpe-lang:platform>419 ····</cpe-lang:platform>
 420 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 421 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 422 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 423 ······</cpe-lang:logical-test>
 424 ····</cpe-lang:platform>
425 ····<cpe-lang:platform·id="not_s390x_arch">425 ····<cpe-lang:platform·id="not_s390x_arch">
426 ······<cpe-lang:logical-test·operator="AND"·negate="false">426 ······<cpe-lang:logical-test·operator="AND"·negate="false">
427 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>427 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
428 ······</cpe-lang:logical-test>428 ······</cpe-lang:logical-test>
429 ····</cpe-lang:platform>429 ····</cpe-lang:platform>
430 ····<cpe-lang:platform·id="package_tmux">430 ····<cpe-lang:platform·id="package_tmux">
431 ······<cpe-lang:logical-test·operator="AND"·negate="false">431 ······<cpe-lang:logical-test·operator="AND"·negate="false">
2.16 MB
./usr/share/xml/scap/ssg/content/ssg-cs10-ds.xml
2.16 MB
./usr/share/xml/scap/ssg/content/ssg-cs10-ds.xml
    
Offset 19, 27 lines modifiedOffset 19, 27 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:10">32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:10">
33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·10</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·10</cpe-dict:title>
34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_centos10:def:1</cpe-dict:check>34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_centos10:def:1</cpe-dict:check>
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ····</cpe-dict:cpe-list>36 ····</cpe-dict:cpe-list>
37 ··</ds:component>37 ··</ds:component>
38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-02-28T20:08:00">38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>
42 ······<xccdf-1.2:description>42 ······<xccdf-1.2:description>
43 ········This·guide·presents·a·catalog·of·security-relevant43 ········This·guide·presents·a·catalog·of·security-relevant
44 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of44 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of
45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 366, 25 lines modifiedOffset 366, 25 lines modified
366 ··········</cpe-lang:logical-test>366 ··········</cpe-lang:logical-test>
367 ········</cpe-lang:platform>367 ········</cpe-lang:platform>
368 ········<cpe-lang:platform·id="package_bash">368 ········<cpe-lang:platform·id="package_bash">
369 ··········<cpe-lang:logical-test·operator="AND"·negate="false">369 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
370 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>370 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
371 ··········</cpe-lang:logical-test>371 ··········</cpe-lang:logical-test>
372 ········</cpe-lang:platform>372 ········</cpe-lang:platform>
373 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
374 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
375 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
376 ··········</cpe-lang:logical-test> 
377 ········</cpe-lang:platform> 
378 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">373 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
379 ··········<cpe-lang:logical-test·operator="AND"·negate="false">374 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
380 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>375 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
381 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>376 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
382 ··········</cpe-lang:logical-test>377 ··········</cpe-lang:logical-test>
383 ········</cpe-lang:platform>378 ········</cpe-lang:platform>
 379 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 380 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 381 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 382 ··········</cpe-lang:logical-test>
 383 ········</cpe-lang:platform>
384 ········<cpe-lang:platform·id="not_s390x_arch">384 ········<cpe-lang:platform·id="not_s390x_arch">
385 ··········<cpe-lang:logical-test·operator="AND"·negate="false">385 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
386 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>386 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
387 ··········</cpe-lang:logical-test>387 ··········</cpe-lang:logical-test>
388 ········</cpe-lang:platform>388 ········</cpe-lang:platform>
389 ········<cpe-lang:platform·id="package_tmux">389 ········<cpe-lang:platform·id="package_tmux">
390 ··········<cpe-lang:logical-test·operator="AND"·negate="false">390 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 213008, 15 lines modifiedOffset 213008, 15 lines modified
213008 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/>213008 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/>
213009 ············</xccdf-1.2:check>213009 ············</xccdf-1.2:check>
213010 ··········</xccdf-1.2:Rule>213010 ··········</xccdf-1.2:Rule>
213011 ········</xccdf-1.2:Group>213011 ········</xccdf-1.2:Group>
213012 ······</xccdf-1.2:Group>213012 ······</xccdf-1.2:Group>
213013 ····</xccdf-1.2:Benchmark>213013 ····</xccdf-1.2:Benchmark>
213014 ··</ds:component>213014 ··</ds:component>
213015 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-02-28T20:08:00">213015 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-03-01T22:08:00">
213016 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">213016 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
213017 ······<oval-def:generator>213017 ······<oval-def:generator>
213018 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>213018 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
213019 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>213019 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
213020 ········<oval:schema_version>5.11</oval:schema_version>213020 ········<oval:schema_version>5.11</oval:schema_version>
213021 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>213021 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
213022 ······</oval-def:generator>213022 ······</oval-def:generator>
Offset 261685, 13145 lines modifiedOffset 261685, 13748 lines modified
261685 ············</oval-def:arithmetic>261685 ············</oval-def:arithmetic>
261686 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>261686 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
261687 ··········</oval-def:arithmetic>261687 ··········</oval-def:arithmetic>
261688 ········</oval-def:local_variable>261688 ········</oval-def:local_variable>
261689 ······</oval-def:variables>261689 ······</oval-def:variables>
261690 ····</oval-def:oval_definitions>261690 ····</oval-def:oval_definitions>
261691 ··</ds:component>261691 ··</ds:component>
261692 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-02-28T20:08:00">261692 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-03-01T22:08:00">
261693 ····<ocil:ocil>261693 ····<ocil:ocil>
261694 ······<ocil:generator>261694 ······<ocil:generator>
261695 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>261695 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
261696 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>261696 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
261697 ········<ocil:schema_version>2.0</ocil:schema_version>261697 ········<ocil:schema_version>2.0</ocil:schema_version>
261698 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>261698 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
261699 ······</ocil:generator>261699 ······</ocil:generator>
261700 ······<ocil:questionnaires>261700 ······<ocil:questionnaires>
261701 ········<ocil:questionnaire·id="ocil:ssg-audit_modify_failed_ppc64le_ocil:questionnaire:1">261701 ········<ocil:questionnaire·id="ocil:ssg-use_pam_wheel_for_su_ocil:questionnaire:1">
261702 ··········<ocil:title>Configure·auditing·of·unsuccessful·file·modifications·(ppc64le)</ocil:title>261702 ··········<ocil:title>Enforce·usage·of·pam_wheel·for·su·authentication</ocil:title>
261703 ··········<ocil:actions>261703 ··········<ocil:actions>
261704 ············<ocil:test_action_ref>ocil:ssg-audit_modify_failed_ppc64le_action:testaction:1</ocil:test_action_ref>261704 ············<ocil:test_action_ref>ocil:ssg-use_pam_wheel_for_su_action:testaction:1</ocil:test_action_ref>
261705 ··········</ocil:actions>261705 ··········</ocil:actions>
261706 ········</ocil:questionnaire>261706 ········</ocil:questionnaire>
261707 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_user_cfg_ocil:questionnaire:1">261707 ········<ocil:questionnaire·id="ocil:ssg-root_permissions_syslibrary_files_ocil:questionnaire:1">
261708 ··········<ocil:title>Verify·/boot/grub2/user.cfg·Permissions</ocil:title>261708 ··········<ocil:title>Verify·the·system-wide·library·files·in·directories
 261709 "/lib",·"/lib64",·"/usr/lib/"·and·"/usr/lib64"·are·group-owned·by·root.</ocil:title>
261709 ··········<ocil:actions>261710 ··········<ocil:actions>
261710 ············<ocil:test_action_ref>ocil:ssg-file_permissions_user_cfg_action:testaction:1</ocil:test_action_ref>261711 ············<ocil:test_action_ref>ocil:ssg-root_permissions_syslibrary_files_action:testaction:1</ocil:test_action_ref>
261711 ··········</ocil:actions>261712 ··········</ocil:actions>
261712 ········</ocil:questionnaire>261713 ········</ocil:questionnaire>
261713 ········<ocil:questionnaire·id="ocil:ssg-accounts_users_home_files_permissions_ocil:questionnaire:1"> 
261714 ··········<ocil:title>All·User·Files·and·Directories·In·The·Home·Directory·Must·Have·Mode·0750·Or·Less·Permissive</ocil:title>261714 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_pubkey_auth_ocil:questionnaire:1">
 261715 ··········<ocil:title>Enable·Public·Key·Authentication</ocil:title>
261715 ··········<ocil:actions>261716 ··········<ocil:actions>
261716 ············<ocil:test_action_ref>ocil:ssg-accounts_users_home_files_permissions_action:testaction:1</ocil:test_action_ref>261717 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
261717 ··········</ocil:actions>261718 ··········</ocil:actions>
261718 ········</ocil:questionnaire>261719 ········</ocil:questionnaire>
261719 ········<ocil:questionnaire·id="ocil:ssg-xwindows_runlevel_target_ocil:questionnaire:1">261720 ········<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
261720 ··········<ocil:title>Disable·Graphical·Environment·Startup·By·Setting·Default·Target</ocil:title>261721 ··········<ocil:title>Enable·systemd-journald·Service</ocil:title>
261721 ··········<ocil:actions>261722 ··········<ocil:actions>
261722 ············<ocil:test_action_ref>ocil:ssg-xwindows_runlevel_target_action:testaction:1</ocil:test_action_ref>261723 ············<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
261723 ··········</ocil:actions>261724 ··········</ocil:actions>
261724 ········</ocil:questionnaire>261725 ········</ocil:questionnaire>
261725 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sudoers_ocil:questionnaire:1">261726 ········<ocil:questionnaire·id="ocil:ssg-disable_ctrlaltdel_burstaction_ocil:questionnaire:1">
261726 ··········<ocil:title>Verify·Group·Who·Owns·/etc/sudoers·File</ocil:title>261727 ··········<ocil:title>Disable·Ctrl-Alt-Del·Burst·Action</ocil:title>
261727 ··········<ocil:actions>261728 ··········<ocil:actions>
261728 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sudoers_action:testaction:1</ocil:test_action_ref>261729 ············<ocil:test_action_ref>ocil:ssg-disable_ctrlaltdel_burstaction_action:testaction:1</ocil:test_action_ref>
261729 ··········</ocil:actions>261730 ··········</ocil:actions>
261730 ········</ocil:questionnaire>261731 ········</ocil:questionnaire>
261731 ········<ocil:questionnaire·id="ocil:ssg-audit_ospp_general_ppc64le_ocil:questionnaire:1">261732 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1">
261732 ··········<ocil:title>Perform·general·configuration·of·Audit·for·OSPP·(ppc64le)</ocil:title>261733 ··········<ocil:title>Disable·kernel·debugfs</ocil:title>
261733 ··········<ocil:actions>261734 ··········<ocil:actions>
261734 ············<ocil:test_action_ref>ocil:ssg-audit_ospp_general_ppc64le_action:testaction:1</ocil:test_action_ref>261735 ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 2252331/2263323 bytes (99.51%) of diff not shown.
2.29 KB
./usr/share/xml/scap/ssg/content/ssg-cs10-xccdf.xml
2.19 KB
./usr/share/xml/scap/ssg/content/ssg-cs10-xccdf.xml
Ordering differences only
    
Offset 329, 25 lines modifiedOffset 329, 25 lines modified
329 ······</cpe-lang:logical-test>329 ······</cpe-lang:logical-test>
330 ····</cpe-lang:platform>330 ····</cpe-lang:platform>
331 ····<cpe-lang:platform·id="package_bash">331 ····<cpe-lang:platform·id="package_bash">
332 ······<cpe-lang:logical-test·operator="AND"·negate="false">332 ······<cpe-lang:logical-test·operator="AND"·negate="false">
333 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>333 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
334 ······</cpe-lang:logical-test>334 ······</cpe-lang:logical-test>
335 ····</cpe-lang:platform>335 ····</cpe-lang:platform>
336 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
337 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
338 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
339 ······</cpe-lang:logical-test> 
340 ····</cpe-lang:platform> 
341 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">336 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
342 ······<cpe-lang:logical-test·operator="AND"·negate="false">337 ······<cpe-lang:logical-test·operator="AND"·negate="false">
343 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>338 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
344 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>339 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
345 ······</cpe-lang:logical-test>340 ······</cpe-lang:logical-test>
346 ····</cpe-lang:platform>341 ····</cpe-lang:platform>
 342 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 343 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 344 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 345 ······</cpe-lang:logical-test>
 346 ····</cpe-lang:platform>
347 ····<cpe-lang:platform·id="not_s390x_arch">347 ····<cpe-lang:platform·id="not_s390x_arch">
348 ······<cpe-lang:logical-test·operator="AND"·negate="false">348 ······<cpe-lang:logical-test·operator="AND"·negate="false">
349 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>349 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
350 ······</cpe-lang:logical-test>350 ······</cpe-lang:logical-test>
351 ····</cpe-lang:platform>351 ····</cpe-lang:platform>
352 ····<cpe-lang:platform·id="package_tmux">352 ····<cpe-lang:platform·id="package_tmux">
353 ······<cpe-lang:logical-test·operator="AND"·negate="false">353 ······<cpe-lang:logical-test·operator="AND"·negate="false">
3.28 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds.xml
3.28 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds.xml
    
Offset 19, 27 lines modifiedOffset 19, 27 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:9">32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:9">
33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·9</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·9</cpe-dict:title>
34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_centos9:def:1</cpe-dict:check>34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_centos9:def:1</cpe-dict:check>
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ····</cpe-dict:cpe-list>36 ····</cpe-dict:cpe-list>
37 ··</ds:component>37 ··</ds:component>
38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-02-28T20:08:00">38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>
42 ······<xccdf-1.2:description>42 ······<xccdf-1.2:description>
43 ········This·guide·presents·a·catalog·of·security-relevant43 ········This·guide·presents·a·catalog·of·security-relevant
44 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of44 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of
45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 433, 25 lines modifiedOffset 433, 25 lines modified
433 ··········</cpe-lang:logical-test>433 ··········</cpe-lang:logical-test>
434 ········</cpe-lang:platform>434 ········</cpe-lang:platform>
435 ········<cpe-lang:platform·id="package_bash">435 ········<cpe-lang:platform·id="package_bash">
436 ··········<cpe-lang:logical-test·operator="AND"·negate="false">436 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
437 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>437 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
438 ··········</cpe-lang:logical-test>438 ··········</cpe-lang:logical-test>
439 ········</cpe-lang:platform>439 ········</cpe-lang:platform>
440 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
441 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
442 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
443 ··········</cpe-lang:logical-test> 
444 ········</cpe-lang:platform> 
445 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">440 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
446 ··········<cpe-lang:logical-test·operator="AND"·negate="false">441 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
447 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>442 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
448 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>443 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
449 ··········</cpe-lang:logical-test>444 ··········</cpe-lang:logical-test>
450 ········</cpe-lang:platform>445 ········</cpe-lang:platform>
 446 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 447 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 448 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 449 ··········</cpe-lang:logical-test>
 450 ········</cpe-lang:platform>
451 ········<cpe-lang:platform·id="not_s390x_arch">451 ········<cpe-lang:platform·id="not_s390x_arch">
452 ··········<cpe-lang:logical-test·operator="AND"·negate="false">452 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
453 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>453 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
454 ··········</cpe-lang:logical-test>454 ··········</cpe-lang:logical-test>
455 ········</cpe-lang:platform>455 ········</cpe-lang:platform>
456 ········<cpe-lang:platform·id="package_tmux">456 ········<cpe-lang:platform·id="package_tmux">
457 ··········<cpe-lang:logical-test·operator="AND"·negate="false">457 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 305658, 15 lines modifiedOffset 305658, 15 lines modified
305658 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>305658 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
305659 ············</xccdf-1.2:check>305659 ············</xccdf-1.2:check>
305660 ··········</xccdf-1.2:Rule>305660 ··········</xccdf-1.2:Rule>
305661 ········</xccdf-1.2:Group>305661 ········</xccdf-1.2:Group>
305662 ······</xccdf-1.2:Group>305662 ······</xccdf-1.2:Group>
305663 ····</xccdf-1.2:Benchmark>305663 ····</xccdf-1.2:Benchmark>
305664 ··</ds:component>305664 ··</ds:component>
305665 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-02-28T20:08:00">305665 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-03-01T22:08:00">
305666 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">305666 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
305667 ······<oval-def:generator>305667 ······<oval-def:generator>
305668 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>305668 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
305669 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>305669 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
305670 ········<oval:schema_version>5.11</oval:schema_version>305670 ········<oval:schema_version>5.11</oval:schema_version>
305671 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>305671 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
305672 ······</oval-def:generator>305672 ······</oval-def:generator>
Offset 371382, 11147 lines modifiedOffset 371382, 11147 lines modified
371382 ············</oval-def:arithmetic>371382 ············</oval-def:arithmetic>
371383 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>371383 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
371384 ··········</oval-def:arithmetic>371384 ··········</oval-def:arithmetic>
371385 ········</oval-def:local_variable>371385 ········</oval-def:local_variable>
371386 ······</oval-def:variables>371386 ······</oval-def:variables>
371387 ····</oval-def:oval_definitions>371387 ····</oval-def:oval_definitions>
371388 ··</ds:component>371388 ··</ds:component>
371389 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-02-28T20:08:00">371389 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-03-01T22:08:00">
371390 ····<ocil:ocil>371390 ····<ocil:ocil>
371391 ······<ocil:generator>371391 ······<ocil:generator>
371392 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>371392 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
371393 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>371393 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
371394 ········<ocil:schema_version>2.0</ocil:schema_version>371394 ········<ocil:schema_version>2.0</ocil:schema_version>
371395 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>371395 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
371396 ······</ocil:generator>371396 ······</ocil:generator>
371397 ······<ocil:questionnaires>371397 ······<ocil:questionnaires>
371398 ········<ocil:questionnaire·id="ocil:ssg-zipl_bls_entries_only_ocil:questionnaire:1"> 
371399 ··········<ocil:title>Ensure·all·zIPL·boot·entries·are·BLS·compliant</ocil:title> 
371400 ··········<ocil:actions> 
371401 ············<ocil:test_action_ref>ocil:ssg-zipl_bls_entries_only_action:testaction:1</ocil:test_action_ref> 
371402 ··········</ocil:actions> 
371403 ········</ocil:questionnaire> 
371404 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_shells_ocil:questionnaire:1">371398 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1">
371405 ··········<ocil:title>Verify·Who·Owns·/etc/shells·File</ocil:title>371399 ··········<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title>
371406 ··········<ocil:actions>371400 ··········<ocil:actions>
371407 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_shells_action:testaction:1</ocil:test_action_ref>371401 ············<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>
371408 ··········</ocil:actions>371402 ··········</ocil:actions>
371409 ········</ocil:questionnaire>371403 ········</ocil:questionnaire>
371410 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sudoers_ocil:questionnaire:1">371404 ········<ocil:questionnaire·id="ocil:ssg-sebool_httpd_enable_cgi_ocil:questionnaire:1">
371411 ··········<ocil:title>Verify·Group·Who·Owns·/etc/sudoers·File</ocil:title>371405 ··········<ocil:title>Configure·the·httpd_enable_cgi·SELinux·Boolean</ocil:title>
371412 ··········<ocil:actions>371406 ··········<ocil:actions>
371413 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sudoers_action:testaction:1</ocil:test_action_ref>371407 ············<ocil:test_action_ref>ocil:ssg-sebool_httpd_enable_cgi_action:testaction:1</ocil:test_action_ref>
371414 ··········</ocil:actions>371408 ··········</ocil:actions>
371415 ········</ocil:questionnaire>371409 ········</ocil:questionnaire>
371416 ········<ocil:questionnaire·id="ocil:ssg-mount_option_boot_efi_nosuid_ocil:questionnaire:1">371410 ········<ocil:questionnaire·id="ocil:ssg-configure_kerberos_crypto_policy_ocil:questionnaire:1">
371417 ··········<ocil:title>Add·nosuid·Option·to·/boot/efi</ocil:title>371411 ··········<ocil:title>Configure·Kerberos·to·use·System·Crypto·Policy</ocil:title>
371418 ··········<ocil:actions>371412 ··········<ocil:actions>
371419 ············<ocil:test_action_ref>ocil:ssg-mount_option_boot_efi_nosuid_action:testaction:1</ocil:test_action_ref>371413 ············<ocil:test_action_ref>ocil:ssg-configure_kerberos_crypto_policy_action:testaction:1</ocil:test_action_ref>
371420 ··········</ocil:actions>371414 ··········</ocil:actions>
371421 ········</ocil:questionnaire>371415 ········</ocil:questionnaire>
371422 ········<ocil:questionnaire·id="ocil:ssg-package_cryptsetup-luks_installed_ocil:questionnaire:1"> 
371423 ··········<ocil:title>Install·cryptsetup·Package</ocil:title>371416 ········<ocil:questionnaire·id="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1">
 371417 ··········<ocil:title>Ensure·SMEP·is·not·disabled·during·boot</ocil:title>
371424 ··········<ocil:actions>371418 ··········<ocil:actions>
371425 ············<ocil:test_action_ref>ocil:ssg-package_cryptsetup-luks_installed_action:testaction:1</ocil:test_action_ref>371419 ············<ocil:test_action_ref>ocil:ssg-grub2_nosmep_argument_absent_action:testaction:1</ocil:test_action_ref>
371426 ··········</ocil:actions>371420 ··········</ocil:actions>
371427 ········</ocil:questionnaire>371421 ········</ocil:questionnaire>
371428 ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_noexec_ocil:questionnaire:1">371422 ········<ocil:questionnaire·id="ocil:ssg-sebool_tftp_home_dir_ocil:questionnaire:1">
371429 ··········<ocil:title>Add·noexec·Option·to·/var/tmp</ocil:title>371423 ··········<ocil:title>Disable·the·tftp_home_dir·SELinux·Boolean</ocil:title>
371430 ··········<ocil:actions>371424 ··········<ocil:actions>
371431 ············<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_noexec_action:testaction:1</ocil:test_action_ref>371425 ············<ocil:test_action_ref>ocil:ssg-sebool_tftp_home_dir_action:testaction:1</ocil:test_action_ref>
371432 ··········</ocil:actions>371426 ··········</ocil:actions>
Max diff block lines reached; 3423602/3434092 bytes (99.69%) of diff not shown.
2.28 KB
./usr/share/xml/scap/ssg/content/ssg-cs9-xccdf.xml
2.18 KB
./usr/share/xml/scap/ssg/content/ssg-cs9-xccdf.xml
Ordering differences only
    
Offset 396, 25 lines modifiedOffset 396, 25 lines modified
396 ······</cpe-lang:logical-test>396 ······</cpe-lang:logical-test>
397 ····</cpe-lang:platform>397 ····</cpe-lang:platform>
398 ····<cpe-lang:platform·id="package_bash">398 ····<cpe-lang:platform·id="package_bash">
399 ······<cpe-lang:logical-test·operator="AND"·negate="false">399 ······<cpe-lang:logical-test·operator="AND"·negate="false">
400 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>400 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
401 ······</cpe-lang:logical-test>401 ······</cpe-lang:logical-test>
402 ····</cpe-lang:platform>402 ····</cpe-lang:platform>
403 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
404 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
405 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
406 ······</cpe-lang:logical-test> 
407 ····</cpe-lang:platform> 
408 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">403 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
409 ······<cpe-lang:logical-test·operator="AND"·negate="false">404 ······<cpe-lang:logical-test·operator="AND"·negate="false">
410 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>405 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
411 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>406 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
412 ······</cpe-lang:logical-test>407 ······</cpe-lang:logical-test>
413 ····</cpe-lang:platform>408 ····</cpe-lang:platform>
 409 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 410 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 411 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 412 ······</cpe-lang:logical-test>
 413 ····</cpe-lang:platform>
414 ····<cpe-lang:platform·id="not_s390x_arch">414 ····<cpe-lang:platform·id="not_s390x_arch">
415 ······<cpe-lang:logical-test·operator="AND"·negate="false">415 ······<cpe-lang:logical-test·operator="AND"·negate="false">
416 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>416 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
417 ······</cpe-lang:logical-test>417 ······</cpe-lang:logical-test>
418 ····</cpe-lang:platform>418 ····</cpe-lang:platform>
419 ····<cpe-lang:platform·id="package_tmux">419 ····<cpe-lang:platform·id="package_tmux">
420 ······<cpe-lang:logical-test·operator="AND"·negate="false">420 ······<cpe-lang:logical-test·operator="AND"·negate="false">
2.05 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds.xml
2.05 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:39">28 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:39">
29 ········<cpe-dict:title·xml:lang="en-us">Fedora·39</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Fedora·39</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:40">32 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:40">
33 ········<cpe-dict:title·xml:lang="en-us">Fedora·40</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Fedora·40</cpe-dict:title>
Offset 51, 15 lines modifiedOffset 51, 15 lines modified
51 ······</cpe-dict:cpe-item>51 ······</cpe-dict:cpe-item>
52 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:45">52 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:45">
53 ········<cpe-dict:title·xml:lang="en-us">Fedora·45</cpe-dict:title>53 ········<cpe-dict:title·xml:lang="en-us">Fedora·45</cpe-dict:title>
54 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>54 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>
55 ······</cpe-dict:cpe-item>55 ······</cpe-dict:cpe-item>
56 ····</cpe-dict:cpe-list>56 ····</cpe-dict:cpe-list>
57 ··</ds:component>57 ··</ds:component>
58 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-xccdf.xml"·timestamp="2025-02-28T20:08:00">58 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-xccdf.xml"·timestamp="2025-03-01T22:08:00">
59 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FEDORA"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">59 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FEDORA"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
60 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>60 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
61 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Fedora</xccdf-1.2:title>61 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Fedora</xccdf-1.2:title>
62 ······<xccdf-1.2:description>62 ······<xccdf-1.2:description>
63 ········This·guide·presents·a·catalog·of·security-relevant63 ········This·guide·presents·a·catalog·of·security-relevant
64 configuration·settings·for·Fedora.·It·is·a·rendering·of64 configuration·settings·for·Fedora.·It·is·a·rendering·of
65 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)65 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 224264, 15 lines modifiedOffset 224264, 15 lines modified
224264 ··············<xccdf-1.2:check-content-ref·href="ssg-fedora-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>224264 ··············<xccdf-1.2:check-content-ref·href="ssg-fedora-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>
224265 ············</xccdf-1.2:check>224265 ············</xccdf-1.2:check>
224266 ··········</xccdf-1.2:Rule>224266 ··········</xccdf-1.2:Rule>
224267 ········</xccdf-1.2:Group>224267 ········</xccdf-1.2:Group>
224268 ······</xccdf-1.2:Group>224268 ······</xccdf-1.2:Group>
224269 ····</xccdf-1.2:Benchmark>224269 ····</xccdf-1.2:Benchmark>
224270 ··</ds:component>224270 ··</ds:component>
224271 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-oval.xml"·timestamp="2025-02-28T20:08:00">224271 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-oval.xml"·timestamp="2025-03-01T22:08:00">
224272 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">224272 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
224273 ······<oval-def:generator>224273 ······<oval-def:generator>
224274 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>224274 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
224275 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>224275 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
224276 ········<oval:schema_version>5.11</oval:schema_version>224276 ········<oval:schema_version>5.11</oval:schema_version>
224277 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>224277 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
224278 ······</oval-def:generator>224278 ······</oval-def:generator>
Offset 273035, 15368 lines modifiedOffset 273035, 15111 lines modified
273035 ············</oval-def:arithmetic>273035 ············</oval-def:arithmetic>
273036 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>273036 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>
273037 ··········</oval-def:arithmetic>273037 ··········</oval-def:arithmetic>
273038 ········</oval-def:local_variable>273038 ········</oval-def:local_variable>
273039 ······</oval-def:variables>273039 ······</oval-def:variables>
273040 ····</oval-def:oval_definitions>273040 ····</oval-def:oval_definitions>
273041 ··</ds:component>273041 ··</ds:component>
273042 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-ocil.xml"·timestamp="2025-02-28T20:08:00">273042 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-ocil.xml"·timestamp="2025-03-01T22:08:00">
273043 ····<ocil:ocil>273043 ····<ocil:ocil>
273044 ······<ocil:generator>273044 ······<ocil:generator>
273045 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>273045 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
273046 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>273046 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
273047 ········<ocil:schema_version>2.0</ocil:schema_version>273047 ········<ocil:schema_version>2.0</ocil:schema_version>
273048 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>273048 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
273049 ······</ocil:generator>273049 ······</ocil:generator>
273050 ······<ocil:questionnaires>273050 ······<ocil:questionnaires>
273051 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fchmodat_ocil:questionnaire:1"> 
273052 ··········<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fchmodat</ocil:title>273051 ········<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1">
 273052 ··········<ocil:title>Ensure·that·/etc/at.deny·does·not·exist</ocil:title>
273053 ··········<ocil:actions>273053 ··········<ocil:actions>
273054 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fchmodat_action:testaction:1</ocil:test_action_ref>273054 ············<ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>
273055 ··········</ocil:actions>273055 ··········</ocil:actions>
273056 ········</ocil:questionnaire>273056 ········</ocil:questionnaire>
273057 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_sudoers_d_ocil:questionnaire:1">273057 ········<ocil:questionnaire·id="ocil:ssg-sudo_require_reauthentication_ocil:questionnaire:1">
273058 ··········<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions·-·/etc/sudoers.d/</ocil:title>273058 ··········<ocil:title>Require·Re-Authentication·When·Using·the·sudo·Command</ocil:title>
273059 ··········<ocil:actions>273059 ··········<ocil:actions>
273060 ············<ocil:test_action_ref>ocil:ssg-audit_rules_sudoers_d_action:testaction:1</ocil:test_action_ref>273060 ············<ocil:test_action_ref>ocil:ssg-sudo_require_reauthentication_action:testaction:1</ocil:test_action_ref>
273061 ··········</ocil:actions>273061 ··········</ocil:actions>
273062 ········</ocil:questionnaire>273062 ········</ocil:questionnaire>
273063 ········<ocil:questionnaire·id="ocil:ssg-file_owner_user_cfg_ocil:questionnaire:1">273063 ········<ocil:questionnaire·id="ocil:ssg-configure_opensc_card_drivers_ocil:questionnaire:1">
273064 ··········<ocil:title>Verify·/boot/grub2/user.cfg·User·Ownership</ocil:title>273064 ··········<ocil:title>Configure·opensc·Smart·Card·Drivers</ocil:title>
273065 ··········<ocil:actions>273065 ··········<ocil:actions>
273066 ············<ocil:test_action_ref>ocil:ssg-file_owner_user_cfg_action:testaction:1</ocil:test_action_ref>273066 ············<ocil:test_action_ref>ocil:ssg-configure_opensc_card_drivers_action:testaction:1</ocil:test_action_ref>
273067 ··········</ocil:actions>273067 ··········</ocil:actions>
273068 ········</ocil:questionnaire>273068 ········</ocil:questionnaire>
273069 ········<ocil:questionnaire·id="ocil:ssg-package_sendmail_removed_ocil:questionnaire:1">273069 ········<ocil:questionnaire·id="ocil:ssg-mount_option_srv_nosuid_ocil:questionnaire:1">
273070 ··········<ocil:title>Uninstall·Sendmail·Package</ocil:title>273070 ··········<ocil:title>Add·nosuid·Option·to·/srv</ocil:title>
273071 ··········<ocil:actions>273071 ··········<ocil:actions>
273072 ············<ocil:test_action_ref>ocil:ssg-package_sendmail_removed_action:testaction:1</ocil:test_action_ref>273072 ············<ocil:test_action_ref>ocil:ssg-mount_option_srv_nosuid_action:testaction:1</ocil:test_action_ref>
273073 ··········</ocil:actions>273073 ··········</ocil:actions>
273074 ········</ocil:questionnaire>273074 ········</ocil:questionnaire>
273075 ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_audit_noexec_ocil:questionnaire:1"> 
273076 ··········<ocil:title>Add·noexec·Option·to·/var/log/audit</ocil:title>273075 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">
 273076 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>
273077 ··········<ocil:actions>273077 ··········<ocil:actions>
273078 ············<ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_noexec_action:testaction:1</ocil:test_action_ref>273078 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>
273079 ··········</ocil:actions>273079 ··········</ocil:actions>
273080 ········</ocil:questionnaire>273080 ········</ocil:questionnaire>
273081 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_max_addresses_ocil:questionnaire:1"> 
273082 ··········<ocil:title>Configure·Maximum·Number·of·Autoconfigured·Addresses·on·All·IPv6·Interfaces·By·Default</ocil:title>273081 ········<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1">
 273082 ··········<ocil:title>Ensure·logrotate·is·Installed</ocil:title>
273083 ··········<ocil:actions>273083 ··········<ocil:actions>
273084 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_max_addresses_action:testaction:1</ocil:test_action_ref>273084 ············<ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref>
273085 ··········</ocil:actions>273085 ··········</ocil:actions>
273086 ········</ocil:questionnaire>273086 ········</ocil:questionnaire>
273087 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_unlinkat_ocil:questionnaire:1"> 
273088 ··········<ocil:title>Record·Successful·Delete·Attempts·to·Files·-·unlinkat</ocil:title>273087 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_ocil:questionnaire:1">
 273088 ··········<ocil:title>Disable·Accepting·Packets·Routed·Between·Local·Interfaces</ocil:title>
273089 ··········<ocil:actions>273089 ··········<ocil:actions>
273090 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_unlinkat_action:testaction:1</ocil:test_action_ref>273090 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_action:testaction:1</ocil:test_action_ref>
273091 ··········</ocil:actions>273091 ··········</ocil:actions>
273092 ········</ocil:questionnaire>273092 ········</ocil:questionnaire>
273093 ········<ocil:questionnaire·id="ocil:ssg-package_geolite2-city_removed_ocil:questionnaire:1"> 
273094 ··········<ocil:title>Uninstall·geolite2-city·Package</ocil:title>273093 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_group_ocil:questionnaire:1">
 273094 ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/group</ocil:title>
273095 ··········<ocil:actions>273095 ··········<ocil:actions>
273096 ············<ocil:test_action_ref>ocil:ssg-package_geolite2-city_removed_action:testaction:1</ocil:test_action_ref>273096 ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_group_action:testaction:1</ocil:test_action_ref>
273097 ··········</ocil:actions>273097 ··········</ocil:actions>
273098 ········</ocil:questionnaire>273098 ········</ocil:questionnaire>
273099 ········<ocil:questionnaire·id="ocil:ssg-no_root_webbrowsing_ocil:questionnaire:1">273099 ········<ocil:questionnaire·id="ocil:ssg-service_ntpd_enabled_ocil:questionnaire:1">
273100 ··········<ocil:title>Restrict·Web·Browser·Use·for·Administrative·Accounts</ocil:title>273100 ··········<ocil:title>Enable·the·NTP·Daemon</ocil:title>
273101 ··········<ocil:actions>273101 ··········<ocil:actions>
273102 ············<ocil:test_action_ref>ocil:ssg-no_root_webbrowsing_action:testaction:1</ocil:test_action_ref>273102 ············<ocil:test_action_ref>ocil:ssg-service_ntpd_enabled_action:testaction:1</ocil:test_action_ref>
273103 ··········</ocil:actions>273103 ··········</ocil:actions>
273104 ········</ocil:questionnaire>273104 ········</ocil:questionnaire>
273105 ········<ocil:questionnaire·id="ocil:ssg-package_tar_installed_ocil:questionnaire:1">273105 ········<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">
273106 ··········<ocil:title>Install·tar·Package</ocil:title>273106 ··········<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>
273107 ··········<ocil:actions>273107 ··········<ocil:actions>
273108 ············<ocil:test_action_ref>ocil:ssg-package_tar_installed_action:testaction:1</ocil:test_action_ref>273108 ············<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 2141455/2152970 bytes (99.47%) of diff not shown.
1.97 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ocil.xml
1.97 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ocil.xml
Ordering differences only
    
Offset 3, 15359 lines modifiedOffset 3, 15102 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fchmodat_ocil:questionnaire:1"> 
11 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fchmodat</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·that·/etc/at.deny·does·not·exist</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fchmodat_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sudoers_d_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-sudo_require_reauthentication_ocil:questionnaire:1">
17 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions·-·/etc/sudoers.d/</ocil:title>17 ······<ocil:title>Require·Re-Authentication·When·Using·the·sudo·Command</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sudoers_d_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sudo_require_reauthentication_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_user_cfg_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-configure_opensc_card_drivers_ocil:questionnaire:1">
23 ······<ocil:title>Verify·/boot/grub2/user.cfg·User·Ownership</ocil:title>23 ······<ocil:title>Configure·opensc·Smart·Card·Drivers</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_owner_user_cfg_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-configure_opensc_card_drivers_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-package_sendmail_removed_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-mount_option_srv_nosuid_ocil:questionnaire:1">
29 ······<ocil:title>Uninstall·Sendmail·Package</ocil:title>29 ······<ocil:title>Add·nosuid·Option·to·/srv</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-package_sendmail_removed_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-mount_option_srv_nosuid_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_audit_noexec_ocil:questionnaire:1"> 
35 ······<ocil:title>Add·noexec·Option·to·/var/log/audit</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">
 35 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_noexec_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_max_addresses_ocil:questionnaire:1"> 
41 ······<ocil:title>Configure·Maximum·Number·of·Autoconfigured·Addresses·on·All·IPv6·Interfaces·By·Default</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1">
 41 ······<ocil:title>Ensure·logrotate·is·Installed</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_max_addresses_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_unlinkat_ocil:questionnaire:1"> 
47 ······<ocil:title>Record·Successful·Delete·Attempts·to·Files·-·unlinkat</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_ocil:questionnaire:1">
 47 ······<ocil:title>Disable·Accepting·Packets·Routed·Between·Local·Interfaces</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_unlinkat_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-package_geolite2-city_removed_ocil:questionnaire:1"> 
53 ······<ocil:title>Uninstall·geolite2-city·Package</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_group_ocil:questionnaire:1">
 53 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/group</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-package_geolite2-city_removed_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_group_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-no_root_webbrowsing_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-service_ntpd_enabled_ocil:questionnaire:1">
59 ······<ocil:title>Restrict·Web·Browser·Use·for·Administrative·Accounts</ocil:title>59 ······<ocil:title>Enable·the·NTP·Daemon</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-no_root_webbrowsing_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-service_ntpd_enabled_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-package_tar_installed_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">
65 ······<ocil:title>Install·tar·Package</ocil:title>65 ······<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-package_tar_installed_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1"> 
71 ······<ocil:title>Limit·the·Number·of·Concurrent·Login·Sessions·Allowed·Per·User</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_private_key_ocil:questionnaire:1">
 71 ······<ocil:title>Verify·Permissions·on·SSH·Server·Private·*_key·Key·Files</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_private_key_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_gssapi_auth_ocil:questionnaire:1">
77 ······<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>77 ······<ocil:title>Enable·GSSAPI·Authentication</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_gssapi_auth_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_priv_separation_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>83 ······<ocil:title>Enable·Use·of·Privilege·Separation</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sshd_use_priv_separation_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1"> 
89 ······<ocil:title>Disable·the·Automounter</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-chronyd_run_as_chrony_user_ocil:questionnaire:1">
 89 ······<ocil:title>Ensure·that·chronyd·is·running·under·chrony·user·account</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-chronyd_run_as_chrony_user_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_fapolicyd_installed_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1">
95 ······<ocil:title>Install·fapolicyd·Package</ocil:title>95 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_fapolicyd_installed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_forward_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_ocil:questionnaire:1">
101 ······<ocil:title>Set·Default·iptables·Policy·for·Forwarded·Packets</ocil:title>101 ······<ocil:title>Configure·Accepting·Prefix·Information·in·Router·Advertisements·on·All·IPv6·Interfaces</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_forward_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_dir_ocil:questionnaire:1"> 
107 ······<ocil:title>Account·Lockouts·Must·Persist</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
 107 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-journald_compress_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·journald·is·configured·to·compress·large·log·files</ocil:title>113 ······<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-journald_compress_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_home_dirs_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-package_vim_installed_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·that·User·Home·Directories·are·not·Group-Writable·or·World-Readable</ocil:title>119 ······<ocil:title>Install·vim·Package</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-file_permissions_home_dirs_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-package_vim_installed_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 2048329/2060771 bytes (99.40%) of diff not shown.
244 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ds.xml
243 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP1:ga:server">28 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP1:ga:server">
29 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP1</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP1</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP2:ga:server">32 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP2:ga:server">
33 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP2</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP2</cpe-dict:title>
Offset 35, 15 lines modifiedOffset 35, 15 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP3:ga:server">36 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP3:ga:server">
37 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP3</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP3</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-xccdf.xml"·timestamp="2025-02-28T20:08:00">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_KYLINSERVER10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_KYLINSERVER10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Kylin·Server·10</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Kylin·Server·10</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·Kylin·Server·10.·It·is·a·rendering·of48 configuration·settings·for·Kylin·Server·10.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 20889, 15 lines modifiedOffset 20889, 15 lines modified
20889 ··············<xccdf-1.2:check-content-ref·href="ssg-kylinserver10-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1"/>20889 ··············<xccdf-1.2:check-content-ref·href="ssg-kylinserver10-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1"/>
20890 ············</xccdf-1.2:check>20890 ············</xccdf-1.2:check>
20891 ··········</xccdf-1.2:Rule>20891 ··········</xccdf-1.2:Rule>
20892 ········</xccdf-1.2:Group>20892 ········</xccdf-1.2:Group>
20893 ······</xccdf-1.2:Group>20893 ······</xccdf-1.2:Group>
20894 ····</xccdf-1.2:Benchmark>20894 ····</xccdf-1.2:Benchmark>
20895 ··</ds:component>20895 ··</ds:component>
20896 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"·timestamp="2025-02-28T20:08:00">20896 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"·timestamp="2025-03-01T22:08:00">
20897 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">20897 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
20898 ······<oval-def:generator>20898 ······<oval-def:generator>
20899 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>20899 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
20900 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>20900 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
20901 ········<oval:schema_version>5.11</oval:schema_version>20901 ········<oval:schema_version>5.11</oval:schema_version>
20902 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>20902 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
20903 ······</oval-def:generator>20903 ······</oval-def:generator>
Offset 26495, 1214 lines modifiedOffset 26495, 1214 lines modified
26495 ············</oval-def:arithmetic>26495 ············</oval-def:arithmetic>
26496 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>26496 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
26497 ··········</oval-def:arithmetic>26497 ··········</oval-def:arithmetic>
26498 ········</oval-def:local_variable>26498 ········</oval-def:local_variable>
26499 ······</oval-def:variables>26499 ······</oval-def:variables>
26500 ····</oval-def:oval_definitions>26500 ····</oval-def:oval_definitions>
26501 ··</ds:component>26501 ··</ds:component>
26502 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"·timestamp="2025-02-28T20:08:00">26502 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"·timestamp="2025-03-01T22:08:00">
26503 ····<ocil:ocil>26503 ····<ocil:ocil>
26504 ······<ocil:generator>26504 ······<ocil:generator>
26505 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>26505 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
26506 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>26506 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
26507 ········<ocil:schema_version>2.0</ocil:schema_version>26507 ········<ocil:schema_version>2.0</ocil:schema_version>
26508 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>26508 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
26509 ······</ocil:generator>26509 ······</ocil:generator>
26510 ······<ocil:questionnaires>26510 ······<ocil:questionnaires>
26511 ········<ocil:questionnaire·id="ocil:ssg-package_net-snmp_removed_ocil:questionnaire:1"> 
26512 ··········<ocil:title>Uninstall·net-snmp·Package</ocil:title> 
26513 ··········<ocil:actions> 
26514 ············<ocil:test_action_ref>ocil:ssg-package_net-snmp_removed_action:testaction:1</ocil:test_action_ref> 
26515 ··········</ocil:actions> 
26516 ········</ocil:questionnaire> 
26517 ········<ocil:questionnaire·id="ocil:ssg-no_files_unowned_by_user_ocil:questionnaire:1"> 
26518 ··········<ocil:title>Ensure·All·Files·Are·Owned·by·a·User</ocil:title> 
26519 ··········<ocil:actions> 
26520 ············<ocil:test_action_ref>ocil:ssg-no_files_unowned_by_user_action:testaction:1</ocil:test_action_ref> 
26521 ··········</ocil:actions> 
26522 ········</ocil:questionnaire> 
26523 ········<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">26511 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">
26524 ··········<ocil:title>Limit·Users'·SSH·Access</ocil:title>26512 ··········<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>
26525 ··········<ocil:actions>26513 ··········<ocil:actions>
26526 ············<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>26514 ············<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>
26527 ··········</ocil:actions>26515 ··········</ocil:actions>
26528 ········</ocil:questionnaire>26516 ········</ocil:questionnaire>
26529 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1"> 
26530 ··········<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv4·Interfaces</ocil:title>26517 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_ctrlaltdel_reboot_ocil:questionnaire:1">
 26518 ··········<ocil:title>Disable·Ctrl-Alt-Del·Reboot·Key·Sequence·in·GNOME3</ocil:title>
26531 ··········<ocil:actions>26519 ··········<ocil:actions>
26532 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>26520 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_ctrlaltdel_reboot_action:testaction:1</ocil:test_action_ref>
26533 ··········</ocil:actions>26521 ··········</ocil:actions>
26534 ········</ocil:questionnaire>26522 ········</ocil:questionnaire>
26535 ········<ocil:questionnaire·id="ocil:ssg-grub2_password_ocil:questionnaire:1">26523 ········<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1">
26536 ··········<ocil:title>Set·Boot·Loader·Password·in·grub2</ocil:title>26524 ··········<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title>
26537 ··········<ocil:actions>26525 ··········<ocil:actions>
26538 ············<ocil:test_action_ref>ocil:ssg-grub2_password_action:testaction:1</ocil:test_action_ref>26526 ············<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref>
26539 ··········</ocil:actions>26527 ··········</ocil:actions>
26540 ········</ocil:questionnaire>26528 ········</ocil:questionnaire>
26541 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">26529 ········<ocil:questionnaire·id="ocil:ssg-package_net-snmp_removed_ocil:questionnaire:1">
26542 ··········<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>26530 ··········<ocil:title>Uninstall·net-snmp·Package</ocil:title>
26543 ··········<ocil:actions>26531 ··········<ocil:actions>
26544 ············<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>26532 ············<ocil:test_action_ref>ocil:ssg-package_net-snmp_removed_action:testaction:1</ocil:test_action_ref>
26545 ··········</ocil:actions>26533 ··········</ocil:actions>
26546 ········</ocil:questionnaire>26534 ········</ocil:questionnaire>
26547 ········<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1">26535 ········<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">
26548 ··········<ocil:title>Ensure·gpgcheck·Enabled·In·Main·dnf·Configuration</ocil:title>26536 ··········<ocil:title>Enable·auditd·Service</ocil:title>
26549 ··········<ocil:actions>26537 ··········<ocil:actions>
26550 ············<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>26538 ············<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>
26551 ··········</ocil:actions>26539 ··········</ocil:actions>
26552 ········</ocil:questionnaire>26540 ········</ocil:questionnaire>
26553 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_ip_forward_ocil:questionnaire:1">26541 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
26554 ··········<ocil:title>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</ocil:title>26542 ··········<ocil:title>Disable·X11·Forwarding</ocil:title>
26555 ··········<ocil:actions>26543 ··········<ocil:actions>
26556 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_forward_action:testaction:1</ocil:test_action_ref>26544 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
26557 ··········</ocil:actions>26545 ··········</ocil:actions>
26558 ········</ocil:questionnaire>26546 ········</ocil:questionnaire>
26559 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1">26547 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">
26560 ··········<ocil:title>Disable·SSH·Support·for·.rhosts·Files</ocil:title>26548 ··········<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>
26561 ··········<ocil:actions>26549 ··········<ocil:actions>
26562 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_action:testaction:1</ocil:test_action_ref>26550 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>
26563 ··········</ocil:actions>26551 ··········</ocil:actions>
26564 ········</ocil:questionnaire>26552 ········</ocil:questionnaire>
26565 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_idle_delay_ocil:questionnaire:1">26553 ········<ocil:questionnaire·id="ocil:ssg-use_pam_wheel_for_su_ocil:questionnaire:1">
26566 ··········<ocil:title>Set·GNOME3·Screensaver·Inactivity·Timeout</ocil:title>26554 ··········<ocil:title>Enforce·usage·of·pam_wheel·for·su·authentication</ocil:title>
26567 ··········<ocil:actions>26555 ··········<ocil:actions>
26568 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_idle_delay_action:testaction:1</ocil:test_action_ref>26556 ············<ocil:test_action_ref>ocil:ssg-use_pam_wheel_for_su_action:testaction:1</ocil:test_action_ref>
26569 ··········</ocil:actions>26557 ··········</ocil:actions>
26570 ········</ocil:questionnaire>26558 ········</ocil:questionnaire>
26571 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_retry_ocil:questionnaire:1">26559 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_shadow_ocil:questionnaire:1">
26572 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Authentication·Retry·Prompts·Permitted·Per-Session</ocil:title>26560 ··········<ocil:title>Verify·User·Who·Owns·shadow·File</ocil:title>
Max diff block lines reached; 237822/249153 bytes (95.45%) of diff not shown.
228 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ocil.xml
228 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ocil.xml
Ordering differences only
    
Offset 3, 1205 lines modifiedOffset 3, 1205 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-package_net-snmp_removed_ocil:questionnaire:1"> 
11 ······<ocil:title>Uninstall·net-snmp·Package</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-package_net-snmp_removed_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-no_files_unowned_by_user_ocil:questionnaire:1"> 
17 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·User</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-no_files_unowned_by_user_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">
23 ······<ocil:title>Limit·Users'·SSH·Access</ocil:title>11 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1"> 
29 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv4·Interfaces</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_ctrlaltdel_reboot_ocil:questionnaire:1">
 17 ······<ocil:title>Disable·Ctrl-Alt-Del·Reboot·Key·Sequence·in·GNOME3</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_ctrlaltdel_reboot_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-grub2_password_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1">
35 ······<ocil:title>Set·Boot·Loader·Password·in·grub2</ocil:title>23 ······<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-grub2_password_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-package_net-snmp_removed_ocil:questionnaire:1">
41 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>29 ······<ocil:title>Uninstall·net-snmp·Package</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-package_net-snmp_removed_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1"> 
47 ······<ocil:title>Ensure·gpgcheck·Enabled·In·Main·dnf·Configuration</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">
 35 ······<ocil:title>Enable·auditd·Service</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_ip_forward_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
53 ······<ocil:title>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</ocil:title>41 ······<ocil:title>Disable·X11·Forwarding</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_forward_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">
59 ······<ocil:title>Disable·SSH·Support·for·.rhosts·Files</ocil:title>47 ······<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_idle_delay_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-use_pam_wheel_for_su_ocil:questionnaire:1">
65 ······<ocil:title>Set·GNOME3·Screensaver·Inactivity·Timeout</ocil:title>53 ······<ocil:title>Enforce·usage·of·pam_wheel·for·su·authentication</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_idle_delay_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-use_pam_wheel_for_su_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_retry_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_shadow_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Authentication·Retry·Prompts·Permitted·Per-Session</ocil:title>59 ······<ocil:title>Verify·User·Who·Owns·shadow·File</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_retry_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_shadow_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-service_sshd_enabled_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_mode_blank_ocil:questionnaire:1">
77 ······<ocil:title>Enable·the·OpenSSH·Service</ocil:title>65 ······<ocil:title>Implement·Blank·Screensaver</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-service_sshd_enabled_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_mode_blank_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_lcredit_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minlen_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Lowercase·Characters</ocil:title>71 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Length</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_lcredit_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minlen_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_mode_blank_ocil:questionnaire:1"> 
89 ······<ocil:title>Implement·Blank·Screensaver</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1">
 77 ······<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_mode_blank_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-set_firewalld_default_zone_ocil:questionnaire:1"> 
95 ······<ocil:title>Set·Default·firewalld·Zone·for·Incoming·Packets</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_unix_remember_ocil:questionnaire:1">
 83 ······<ocil:title>Limit·Password·Reuse</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-set_firewalld_default_zone_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_remember_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-use_pam_wheel_for_su_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1">
101 ······<ocil:title>Enforce·usage·of·pam_wheel·for·su·authentication</ocil:title>89 ······<ocil:title>Set·Password·Warning·Age</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-use_pam_wheel_for_su_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-aide_periodic_cron_checking_ocil:questionnaire:1">
107 ······<ocil:title>Limit·the·Number·of·Concurrent·Login·Sessions·Allowed·Per·User</ocil:title>95 ······<ocil:title>Configure·Periodic·Execution·of·AIDE</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-aide_periodic_cron_checking_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_permissions_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_permissions_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·System·Log·Files·Have·Correct·Permissions</ocil:title>101 ······<ocil:title>Ensure·System·Log·Files·Have·Correct·Permissions</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_permissions_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_permissions_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sshd_allow_only_protocol2_ocil:questionnaire:1"> 
119 ······<ocil:title>Allow·Only·SSH·Protocol·2</ocil:title> 
120 ······<ocil:actions> 
121 ········<ocil:test_action_ref>ocil:ssg-sshd_allow_only_protocol2_action:testaction:1</ocil:test_action_ref> 
122 ······</ocil:actions> 
123 ····</ocil:questionnaire> 
124 ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-package_rsync_removed_ocil:questionnaire:1">
125 ······<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title>107 ······<ocil:title>Uninstall·rsync·Package</ocil:title>
Max diff block lines reached; 221919/233267 bytes (95.14%) of diff not shown.
5.76 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ds.xml
5.65 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:apple:macos:10.15">28 ······<cpe-dict:cpe-item·name="cpe:/o:apple:macos:10.15">
29 ········<cpe-dict:title·xml:lang="en-us">Apple·macOS·10.15</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Apple·macOS·10.15</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-macos1015-cpe-oval.xml">oval:ssg-installed_OS_is_macos1015:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-macos1015-cpe-oval.xml">oval:ssg-installed_OS_is_macos1015:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of40 configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 563, 15 lines modifiedOffset 563, 15 lines modified
563 ··············<xccdf-1.2:check-content-ref·href="ssg-macos1015-ocil.xml"·name="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"/>563 ··············<xccdf-1.2:check-content-ref·href="ssg-macos1015-ocil.xml"·name="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"/>
564 ············</xccdf-1.2:check>564 ············</xccdf-1.2:check>
565 ··········</xccdf-1.2:Rule>565 ··········</xccdf-1.2:Rule>
566 ········</xccdf-1.2:Group>566 ········</xccdf-1.2:Group>
567 ······</xccdf-1.2:Group>567 ······</xccdf-1.2:Group>
568 ····</xccdf-1.2:Benchmark>568 ····</xccdf-1.2:Benchmark>
569 ··</ds:component>569 ··</ds:component>
570 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-oval.xml"·timestamp="2025-02-28T20:08:00">570 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-oval.xml"·timestamp="2025-03-01T22:08:00">
571 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">571 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
572 ······<oval-def:generator>572 ······<oval-def:generator>
573 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>573 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
574 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>574 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
575 ········<oval:schema_version>5.11</oval:schema_version>575 ········<oval:schema_version>5.11</oval:schema_version>
576 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>576 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
577 ······</oval-def:generator>577 ······</oval-def:generator>
Offset 600, 15 lines modifiedOffset 600, 15 lines modified
600 ··········<ind:filepath>/etc/security/audit_control</ind:filepath>600 ··········<ind:filepath>/etc/security/audit_control</ind:filepath>
601 ··········<ind:pattern·operation="pattern·match">^policy:.*,ahlt.*$</ind:pattern>601 ··········<ind:pattern·operation="pattern·match">^policy:.*,ahlt.*$</ind:pattern>
602 ··········<ind:instance·datatype="int">1</ind:instance>602 ··········<ind:instance·datatype="int">1</ind:instance>
603 ········</ind:textfilecontent54_object>603 ········</ind:textfilecontent54_object>
604 ······</oval-def:objects>604 ······</oval-def:objects>
605 ····</oval-def:oval_definitions>605 ····</oval-def:oval_definitions>
606 ··</ds:component>606 ··</ds:component>
607 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-ocil.xml"·timestamp="2025-02-28T20:08:00">607 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-ocil.xml"·timestamp="2025-03-01T22:08:00">
608 ····<ocil:ocil>608 ····<ocil:ocil>
609 ······<ocil:generator>609 ······<ocil:generator>
610 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>610 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
611 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>611 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
612 ········<ocil:schema_version>2.0</ocil:schema_version>612 ········<ocil:schema_version>2.0</ocil:schema_version>
613 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>613 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
614 ······</ocil:generator>614 ······</ocil:generator>
Offset 659, 15 lines modifiedOffset 659, 15 lines modified
659 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control659 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control
660 The·output·should·contain·ahlt660 The·output·should·contain·ahlt
661 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text>661 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text>
662 ········</ocil:boolean_question>662 ········</ocil:boolean_question>
663 ······</ocil:questions>663 ······</ocil:questions>
664 ····</ocil:ocil>664 ····</ocil:ocil>
665 ··</ds:component>665 ··</ds:component>
666 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"·timestamp="2025-02-28T20:08:00">666 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"·timestamp="2025-03-01T22:08:00">
667 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">667 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
668 ······<oval-def:generator>668 ······<oval-def:generator>
669 ········<oval:product_name>build_cpe.py·from·SCAP·Security·Guide</oval:product_name>669 ········<oval:product_name>build_cpe.py·from·SCAP·Security·Guide</oval:product_name>
670 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>670 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
671 ········<oval:schema_version>5.11</oval:schema_version>671 ········<oval:schema_version>5.11</oval:schema_version>
672 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>672 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
673 ······</oval-def:generator>673 ······</oval-def:generator>
882 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds.xml
882 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.1">28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.1">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.10">32 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.10">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4.10</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4.10</cpe-dict:title>
Offset 111, 15 lines modifiedOffset 111, 15 lines modified
111 ······</cpe-dict:cpe-item>111 ······</cpe-dict:cpe-item>
112 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:openshift_container_platform_node:4">112 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:openshift_container_platform_node:4">
113 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4·Node</cpe-dict:title>113 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4·Node</cpe-dict:title>
114 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4_node:def:1</cpe-dict:check>114 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4_node:def:1</cpe-dict:check>
115 ······</cpe-dict:cpe-item>115 ······</cpe-dict:cpe-item>
116 ····</cpe-dict:cpe-list>116 ····</cpe-dict:cpe-list>
117 ··</ds:component>117 ··</ds:component>
118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-xccdf.xml"·timestamp="2025-02-28T20:08:00">118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-xccdf.xml"·timestamp="2025-03-01T22:08:00">
119 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OCP-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">119 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OCP-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
120 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>120 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
121 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container·Platform·4</xccdf-1.2:title>121 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container·Platform·4</xccdf-1.2:title>
122 ······<xccdf-1.2:description>122 ······<xccdf-1.2:description>
123 ········This·guide·presents·a·catalog·of·security-relevant123 ········This·guide·presents·a·catalog·of·security-relevant
124 configuration·settings·for·Red·Hat·OpenShift·Container·Platform·4.·It·is·a·rendering·of124 configuration·settings·for·Red·Hat·OpenShift·Container·Platform·4.·It·is·a·rendering·of
125 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)125 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 22582, 15 lines modifiedOffset 22582, 15 lines modified
22582 ··············<xccdf-1.2:check-content-ref·href="ssg-ocp4-ocil.xml"·name="ocil:ssg-file_permissions_worker_service_ocil:questionnaire:1"/>22582 ··············<xccdf-1.2:check-content-ref·href="ssg-ocp4-ocil.xml"·name="ocil:ssg-file_permissions_worker_service_ocil:questionnaire:1"/>
22583 ············</xccdf-1.2:check>22583 ············</xccdf-1.2:check>
22584 ··········</xccdf-1.2:Rule>22584 ··········</xccdf-1.2:Rule>
22585 ········</xccdf-1.2:Group>22585 ········</xccdf-1.2:Group>
22586 ······</xccdf-1.2:Group>22586 ······</xccdf-1.2:Group>
22587 ····</xccdf-1.2:Benchmark>22587 ····</xccdf-1.2:Benchmark>
22588 ··</ds:component>22588 ··</ds:component>
22589 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-oval.xml"·timestamp="2025-02-28T20:08:00">22589 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-oval.xml"·timestamp="2025-03-01T22:08:00">
22590 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">22590 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
22591 ······<oval-def:generator>22591 ······<oval-def:generator>
22592 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>22592 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
22593 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>22593 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
22594 ········<oval:schema_version>5.11</oval:schema_version>22594 ········<oval:schema_version>5.11</oval:schema_version>
22595 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>22595 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
22596 ······</oval-def:generator>22596 ······</oval-def:generator>
Offset 34382, 4742 lines modifiedOffset 34382, 4742 lines modified
34382 ············<oval-def:variable_component·var_ref="oval:ssg-ocp_data_root:var:1"/>34382 ············<oval-def:variable_component·var_ref="oval:ssg-ocp_data_root:var:1"/>
34383 ············<oval-def:literal_component>/apis/apps/v1/namespaces/openshift-ingress/deployments/router-default#aa685c2fe85cfde2ec878952fdd5e72b0824bdaccd1063efcfc29fea8137840c</oval-def:literal_component>34383 ············<oval-def:literal_component>/apis/apps/v1/namespaces/openshift-ingress/deployments/router-default#aa685c2fe85cfde2ec878952fdd5e72b0824bdaccd1063efcfc29fea8137840c</oval-def:literal_component>
34384 ··········</oval-def:concat>34384 ··········</oval-def:concat>
34385 ········</oval-def:local_variable>34385 ········</oval-def:local_variable>
34386 ······</oval-def:variables>34386 ······</oval-def:variables>
34387 ····</oval-def:oval_definitions>34387 ····</oval-def:oval_definitions>
34388 ··</ds:component>34388 ··</ds:component>
34389 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-ocil.xml"·timestamp="2025-02-28T20:08:00">34389 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-ocil.xml"·timestamp="2025-03-01T22:08:00">
34390 ····<ocil:ocil>34390 ····<ocil:ocil>
34391 ······<ocil:generator>34391 ······<ocil:generator>
34392 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>34392 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
34393 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>34393 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
34394 ········<ocil:schema_version>2.0</ocil:schema_version>34394 ········<ocil:schema_version>2.0</ocil:schema_version>
34395 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>34395 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
34396 ······</ocil:generator>34396 ······</ocil:generator>
34397 ······<ocil:questionnaires>34397 ······<ocil:questionnaires>
34398 ········<ocil:questionnaire·id="ocil:ssg-file_owner_ovs_sys_id_conf_ocil:questionnaire:1">34398 ········<ocil:questionnaire·id="ocil:ssg-file_owner_ovs_sys_id_conf_ocil:questionnaire:1">
34399 ··········<ocil:title>Verify·User·Who·Owns·The·Open·vSwitch·Persistent·System·ID</ocil:title>34399 ··········<ocil:title>Verify·User·Who·Owns·The·Open·vSwitch·Persistent·System·ID</ocil:title>
34400 ··········<ocil:actions>34400 ··········<ocil:actions>
34401 ············<ocil:test_action_ref>ocil:ssg-file_owner_ovs_sys_id_conf_action:testaction:1</ocil:test_action_ref>34401 ············<ocil:test_action_ref>ocil:ssg-file_owner_ovs_sys_id_conf_action:testaction:1</ocil:test_action_ref>
34402 ··········</ocil:actions>34402 ··········</ocil:actions>
34403 ········</ocil:questionnaire>34403 ········</ocil:questionnaire>
34404 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_multus_conf_ocil:questionnaire:1">34404 ········<ocil:questionnaire·id="ocil:ssg-file_owner_kubeconfig_ocil:questionnaire:1">
 34405 ··········<ocil:title>Verify·User·Who·Owns·The·OpenShift·Admin·Kubeconfig·File</ocil:title>
34405 ··········<ocil:title>Verify·Group·Who·Owns·The·OpenShift·Multus·Container·Network·Interface·Plugin·Files</ocil:title> 
34406 ··········<ocil:actions> 
34407 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_multus_conf_action:testaction:1</ocil:test_action_ref> 
34408 ··········</ocil:actions> 
34409 ········</ocil:questionnaire> 
34410 ········<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_soft_imagefs_inodesfree_ocil:questionnaire:1"> 
34411 ··········<ocil:title>Ensure·Eviction·threshold·Settings·Are·Set·-·evictionSoft:·imagefs.inodesFree</ocil:title> 
34412 ··········<ocil:actions>34406 ··········<ocil:actions>
34413 ············<ocil:test_action_ref>ocil:ssg-kubelet_eviction_thresholds_set_soft_imagefs_inodesfree_action:testaction:1</ocil:test_action_ref>34407 ············<ocil:test_action_ref>ocil:ssg-file_owner_kubeconfig_action:testaction:1</ocil:test_action_ref>
34414 ··········</ocil:actions>34408 ··········</ocil:actions>
34415 ········</ocil:questionnaire>34409 ········</ocil:questionnaire>
34416 ········<ocil:questionnaire·id="ocil:ssg-api_server_audit_log_maxsize_ocil:questionnaire:1"> 
34417 ··········<ocil:title>Configure·Kubernetes·API·Server·Maximum·Audit·Log·Size</ocil:title>34410 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_openshift_pki_key_files_ocil:questionnaire:1">
 34411 ··········<ocil:title>Verify·Group·Who·Owns·The·OpenShift·PKI·Private·Key·Files</ocil:title>
34418 ··········<ocil:actions>34412 ··········<ocil:actions>
34419 ············<ocil:test_action_ref>ocil:ssg-api_server_audit_log_maxsize_action:testaction:1</ocil:test_action_ref>34413 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_openshift_pki_key_files_action:testaction:1</ocil:test_action_ref>
34420 ··········</ocil:actions>34414 ··········</ocil:actions>
34421 ········</ocil:questionnaire>34415 ········</ocil:questionnaire>
34422 ········<ocil:questionnaire·id="ocil:ssg-api_server_admission_control_plugin_alwayspullimages_ocil:questionnaire:1"> 
34423 ··········<ocil:title>Ensure·that·the·Admission·Control·Plugin·AlwaysPullImages·is·not·set</ocil:title>34416 ········<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_soft_nodefs_available_ocil:questionnaire:1">
 34417 ··········<ocil:title>Ensure·Eviction·threshold·Settings·Are·Set·-·evictionSoft:·nodefs.available</ocil:title>
34424 ··········<ocil:actions>34418 ··········<ocil:actions>
34425 ············<ocil:test_action_ref>ocil:ssg-api_server_admission_control_plugin_alwayspullimages_action:testaction:1</ocil:test_action_ref>34419 ············<ocil:test_action_ref>ocil:ssg-kubelet_eviction_thresholds_set_soft_nodefs_available_action:testaction:1</ocil:test_action_ref>
34426 ··········</ocil:actions>34420 ··········</ocil:actions>
34427 ········</ocil:questionnaire>34421 ········</ocil:questionnaire>
34428 ········<ocil:questionnaire·id="ocil:ssg-cluster_version_operator_exists_ocil:questionnaire:1">34422 ········<ocil:questionnaire·id="ocil:ssg-etcd_peer_client_cert_auth_ocil:questionnaire:1">
34429 ··········<ocil:title>Ensure·that·Cluster·Version·Operator·is·deployed</ocil:title>34423 ··········<ocil:title>Enable·The·Peer·Client·Certificate·Authentication</ocil:title>
34430 ··········<ocil:actions>34424 ··········<ocil:actions>
34431 ············<ocil:test_action_ref>ocil:ssg-cluster_version_operator_exists_action:testaction:1</ocil:test_action_ref>34425 ············<ocil:test_action_ref>ocil:ssg-etcd_peer_client_cert_auth_action:testaction:1</ocil:test_action_ref>
34432 ··········</ocil:actions>34426 ··········</ocil:actions>
34433 ········</ocil:questionnaire>34427 ········</ocil:questionnaire>
34434 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_scheduler_kubeconfig_ocil:questionnaire:1"> 
34435 ··········<ocil:title>Verify·Permissions·on·the·Kubernetes·Scheduler·Kubeconfig·File</ocil:title>34428 ········<ocil:questionnaire·id="ocil:ssg-api_server_no_adm_ctrl_plugins_disabled_ocil:questionnaire:1">
 34429 ··········<ocil:title>Ensure·all·admission·control·plugins·are·enabled</ocil:title>
34436 ··········<ocil:actions>34430 ··········<ocil:actions>
34437 ············<ocil:test_action_ref>ocil:ssg-file_permissions_scheduler_kubeconfig_action:testaction:1</ocil:test_action_ref>34431 ············<ocil:test_action_ref>ocil:ssg-api_server_no_adm_ctrl_plugins_disabled_action:testaction:1</ocil:test_action_ref>
34438 ··········</ocil:actions>34432 ··········</ocil:actions>
34439 ········</ocil:questionnaire>34433 ········</ocil:questionnaire>
34440 ········<ocil:questionnaire·id="ocil:ssg-audit_error_alert_exists_ocil:questionnaire:1">34434 ········<ocil:questionnaire·id="ocil:ssg-rbac_wildcard_use_ocil:questionnaire:1">
34441 ··········<ocil:title>Ensure·that·Audit·Log·Errors·Emit·Alerts</ocil:title>34435 ··········<ocil:title>Minimize·Wildcard·Usage·in·Cluster·and·Local·Roles</ocil:title>
34442 ··········<ocil:actions>34436 ··········<ocil:actions>
34443 ············<ocil:test_action_ref>ocil:ssg-audit_error_alert_exists_action:testaction:1</ocil:test_action_ref>34437 ············<ocil:test_action_ref>ocil:ssg-rbac_wildcard_use_action:testaction:1</ocil:test_action_ref>
34444 ··········</ocil:actions>34438 ··········</ocil:actions>
34445 ········</ocil:questionnaire>34439 ········</ocil:questionnaire>
34446 ········<ocil:questionnaire·id="ocil:ssg-etcd_backup_ocil:questionnaire:1">34440 ········<ocil:questionnaire·id="ocil:ssg-api_server_audit_log_maxbackup_ocil:questionnaire:1">
34447 ··········<ocil:title>Configure·Recurring·Backups·For·etcd</ocil:title>34441 ··········<ocil:title>Configure·the·Kubernetes·API·Server·Maximum·Retained·Audit·Logs</ocil:title>
34448 ··········<ocil:actions>34442 ··········<ocil:actions>
34449 ············<ocil:test_action_ref>ocil:ssg-etcd_backup_action:testaction:1</ocil:test_action_ref>34443 ············<ocil:test_action_ref>ocil:ssg-api_server_audit_log_maxbackup_action:testaction:1</ocil:test_action_ref>
34450 ··········</ocil:actions>34444 ··········</ocil:actions>
34451 ········</ocil:questionnaire>34445 ········</ocil:questionnaire>
34452 ········<ocil:questionnaire·id="ocil:ssg-default_ingress_ca_replaced_ocil:questionnaire:1">34446 ········<ocil:questionnaire·id="ocil:ssg-kubelet_configure_tls_min_version_ocil:questionnaire:1">
34453 ··········<ocil:title>Ensure·that·the·default·Ingress·CA·(wildcard·issuer)·has·been·replaced</ocil:title>34447 ··········<ocil:title>Ensure·Kubelet·is·configured·with·allowed·TLS·versions</ocil:title>
34454 ··········<ocil:actions>34448 ··········<ocil:actions>
34455 ············<ocil:test_action_ref>ocil:ssg-default_ingress_ca_replaced_action:testaction:1</ocil:test_action_ref>34449 ············<ocil:test_action_ref>ocil:ssg-kubelet_configure_tls_min_version_action:testaction:1</ocil:test_action_ref>
34456 ··········</ocil:actions>34450 ··········</ocil:actions>
Max diff block lines reached; 891378/902966 bytes (98.72%) of diff not shown.
845 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ocil.xml
845 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ocil.xml
Ordering differences only
    
Offset 9, 4727 lines modifiedOffset 9, 4727 lines modified
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_ovs_sys_id_conf_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_ovs_sys_id_conf_ocil:questionnaire:1">
11 ······<ocil:title>Verify·User·Who·Owns·The·Open·vSwitch·Persistent·System·ID</ocil:title>11 ······<ocil:title>Verify·User·Who·Owns·The·Open·vSwitch·Persistent·System·ID</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-file_owner_ovs_sys_id_conf_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_owner_ovs_sys_id_conf_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_multus_conf_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_owner_kubeconfig_ocil:questionnaire:1">
 17 ······<ocil:title>Verify·User·Who·Owns·The·OpenShift·Admin·Kubeconfig·File</ocil:title>
17 ······<ocil:title>Verify·Group·Who·Owns·The·OpenShift·Multus·Container·Network·Interface·Plugin·Files</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_multus_conf_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_soft_imagefs_inodesfree_ocil:questionnaire:1"> 
23 ······<ocil:title>Ensure·Eviction·threshold·Settings·Are·Set·-·evictionSoft:·imagefs.inodesFree</ocil:title> 
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-kubelet_eviction_thresholds_set_soft_imagefs_inodesfree_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_owner_kubeconfig_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-api_server_audit_log_maxsize_ocil:questionnaire:1"> 
29 ······<ocil:title>Configure·Kubernetes·API·Server·Maximum·Audit·Log·Size</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_openshift_pki_key_files_ocil:questionnaire:1">
 23 ······<ocil:title>Verify·Group·Who·Owns·The·OpenShift·PKI·Private·Key·Files</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-api_server_audit_log_maxsize_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_openshift_pki_key_files_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-api_server_admission_control_plugin_alwayspullimages_ocil:questionnaire:1"> 
35 ······<ocil:title>Ensure·that·the·Admission·Control·Plugin·AlwaysPullImages·is·not·set</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_soft_nodefs_available_ocil:questionnaire:1">
 29 ······<ocil:title>Ensure·Eviction·threshold·Settings·Are·Set·-·evictionSoft:·nodefs.available</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-api_server_admission_control_plugin_alwayspullimages_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kubelet_eviction_thresholds_set_soft_nodefs_available_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-cluster_version_operator_exists_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-etcd_peer_client_cert_auth_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·that·Cluster·Version·Operator·is·deployed</ocil:title>35 ······<ocil:title>Enable·The·Peer·Client·Certificate·Authentication</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-cluster_version_operator_exists_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-etcd_peer_client_cert_auth_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_scheduler_kubeconfig_ocil:questionnaire:1"> 
47 ······<ocil:title>Verify·Permissions·on·the·Kubernetes·Scheduler·Kubeconfig·File</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-api_server_no_adm_ctrl_plugins_disabled_ocil:questionnaire:1">
 41 ······<ocil:title>Ensure·all·admission·control·plugins·are·enabled</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_permissions_scheduler_kubeconfig_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-api_server_no_adm_ctrl_plugins_disabled_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_error_alert_exists_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-rbac_wildcard_use_ocil:questionnaire:1">
53 ······<ocil:title>Ensure·that·Audit·Log·Errors·Emit·Alerts</ocil:title>47 ······<ocil:title>Minimize·Wildcard·Usage·in·Cluster·and·Local·Roles</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_error_alert_exists_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-rbac_wildcard_use_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-etcd_backup_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-api_server_audit_log_maxbackup_ocil:questionnaire:1">
59 ······<ocil:title>Configure·Recurring·Backups·For·etcd</ocil:title>53 ······<ocil:title>Configure·the·Kubernetes·API·Server·Maximum·Retained·Audit·Logs</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-etcd_backup_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-api_server_audit_log_maxbackup_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-default_ingress_ca_replaced_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_tls_min_version_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·that·the·default·Ingress·CA·(wildcard·issuer)·has·been·replaced</ocil:title>59 ······<ocil:title>Ensure·Kubelet·is·configured·with·allowed·TLS·versions</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-default_ingress_ca_replaced_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_tls_min_version_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_pod_logs_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_ca_ocil:questionnaire:1">
71 ······<ocil:title>Kubernetes·Pod·Logs·Must·Be·Owned·By·Root</ocil:title>65 ······<ocil:title>Verify·User·Who·Owns·the·Worker·Certificate·Authority·File</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_owner_pod_logs_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_owner_worker_ca_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_ovs_vswitchd_pid_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-api_server_tls_private_key_ocil:questionnaire:1">
77 ······<ocil:title>Verify·Group·Who·Owns·The·Open·vSwitch·Daemon·PID·File</ocil:title>71 ······<ocil:title>Configure·the·Certificate·Key·for·the·API·Server</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_ovs_vswitchd_pid_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-api_server_tls_private_key_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-resource_requests_quota_cluster_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-resource_requests_limits_in_statefulset_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·workloads·use·cluster·resource·requests·and·limits</ocil:title>77 ······<ocil:title>Ensure·that·all·statefulsets·has·resource·limits</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-resource_requests_quota_cluster_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-resource_requests_limits_in_statefulset_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_kube_apiserver_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ovn_db_files_ocil:questionnaire:1">
89 ······<ocil:title>Verify·Group·Who·Owns·The·Kubernetes·API·Server·Pod·Specification·File</ocil:title>83 ······<ocil:title>Verify·Permissions·on·the·OVNKubernetes·DB·files</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_kube_apiserver_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_ovn_db_files_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-rbac_logging_mod_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-project_config_and_template_resource_quota_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·that·the·ClusterLogging·and·ClusterLoggingForwarder·resources·are·protected·from·unauthorized·modification</ocil:title>89 ······<ocil:title>Ensure·that·project·templates·autocreate·Resource·Quotas</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-rbac_logging_mod_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-project_config_and_template_resource_quota_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etcd_member_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-rbac_least_privilege_ocil:questionnaire:1">
101 ······<ocil:title>Verify·Group·Who·Owns·The·etcd·Member·Pod·Specification·File</ocil:title>95 ······<ocil:title>Ensure·that·the·RBAC·setup·follows·the·principle·of·least·privilege</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etcd_member_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-rbac_least_privilege_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_tls_cipher_suites_kubeapiserver_operator_ocil:questionnaire:1"> 
107 ······<ocil:title>Ensure·that·the·Kubernetes·API·Server·Operator·only·makes·use·of·Strong·Cryptographic·Ciphers</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-file_owner_multus_conf_ocil:questionnaire:1">
 101 ······<ocil:title>Verify·User·Who·Owns·The·OpenShift·Multus·Container·Network·Interface·Plugin·Files</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_tls_cipher_suites_kubeapiserver_operator_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_owner_multus_conf_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-api_server_tls_cipher_suites_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_owner_kube_controller_manager_ocil:questionnaire:1">
113 ······<ocil:title>Use·Strong·Cryptographic·Ciphers·on·the·API·Server</ocil:title>107 ······<ocil:title>Verify·User·Who·Owns·The·Kubernetes·Controller·Manager·Pod·Specification·File</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-api_server_tls_cipher_suites_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_owner_kube_controller_manager_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-ocp_allowed_registries_ocil:questionnaire:1">
119 ······<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>113 ······<ocil:title>Allowed·registries·are·configured</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-ocp_allowed_registries_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_proxy_kubeconfig_ocil:questionnaire:1"> 
125 ······<ocil:title>Verify·Group·Who·Owns·The·Worker·Proxy·Kubeconfig·File</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-api_server_openshift_https_serving_cert_ocil:questionnaire:1">
 119 ······<ocil:title>Ensure·the·openshift-oauth-apiserver·service·uses·TLS</ocil:title>
126 ······<ocil:actions>120 ······<ocil:actions>
127 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_proxy_kubeconfig_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-api_server_openshift_https_serving_cert_action:testaction:1</ocil:test_action_ref>
128 ······</ocil:actions>122 ······</ocil:actions>
129 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
Max diff block lines reached; 851399/864664 bytes (98.47%) of diff not shown.
1.81 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ds.xml
1.81 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:10">28 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:10">
29 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·10</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·10</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml">oval:ssg-installed_OS_is_ol10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml">oval:ssg-installed_OS_is_ol10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·10</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·10</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Oracle·Linux·10.·It·is·a·rendering·of40 configuration·settings·for·Oracle·Linux·10.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 194138, 15 lines modifiedOffset 194138, 15 lines modified
194138 ··············<xccdf-1.2:check-content-ref·href="ssg-ol10-ocil.xml"·name="ocil:ssg-audit_access_success_ocil:questionnaire:1"/>194138 ··············<xccdf-1.2:check-content-ref·href="ssg-ol10-ocil.xml"·name="ocil:ssg-audit_access_success_ocil:questionnaire:1"/>
194139 ············</xccdf-1.2:check>194139 ············</xccdf-1.2:check>
194140 ··········</xccdf-1.2:Rule>194140 ··········</xccdf-1.2:Rule>
194141 ········</xccdf-1.2:Group>194141 ········</xccdf-1.2:Group>
194142 ······</xccdf-1.2:Group>194142 ······</xccdf-1.2:Group>
194143 ····</xccdf-1.2:Benchmark>194143 ····</xccdf-1.2:Benchmark>
194144 ··</ds:component>194144 ··</ds:component>
194145 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-oval.xml"·timestamp="2025-02-28T20:08:00">194145 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-oval.xml"·timestamp="2025-03-01T22:08:00">
194146 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">194146 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
194147 ······<oval-def:generator>194147 ······<oval-def:generator>
194148 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>194148 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
194149 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>194149 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
194150 ········<oval:schema_version>5.11</oval:schema_version>194150 ········<oval:schema_version>5.11</oval:schema_version>
194151 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>194151 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
194152 ······</oval-def:generator>194152 ······</oval-def:generator>
Offset 237580, 12092 lines modifiedOffset 237580, 12159 lines modified
237580 ············</oval-def:arithmetic>237580 ············</oval-def:arithmetic>
237581 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>237581 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
237582 ··········</oval-def:arithmetic>237582 ··········</oval-def:arithmetic>
237583 ········</oval-def:local_variable>237583 ········</oval-def:local_variable>
237584 ······</oval-def:variables>237584 ······</oval-def:variables>
237585 ····</oval-def:oval_definitions>237585 ····</oval-def:oval_definitions>
237586 ··</ds:component>237586 ··</ds:component>
237587 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-ocil.xml"·timestamp="2025-02-28T20:08:00">237587 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-ocil.xml"·timestamp="2025-03-01T22:08:00">
237588 ····<ocil:ocil>237588 ····<ocil:ocil>
237589 ······<ocil:generator>237589 ······<ocil:generator>
237590 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>237590 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
237591 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>237591 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
237592 ········<ocil:schema_version>2.0</ocil:schema_version>237592 ········<ocil:schema_version>2.0</ocil:schema_version>
237593 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>237593 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
237594 ······</ocil:generator>237594 ······</ocil:generator>
237595 ······<ocil:questionnaires>237595 ······<ocil:questionnaires>
237596 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">237596 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_suid_privilege_function_ocil:questionnaire:1">
 237597 ··········<ocil:title>Record·Events·When·Privileged·Executables·Are·Run</ocil:title>
237597 ··········<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title> 
237598 ··········<ocil:actions> 
237599 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref> 
237600 ··········</ocil:actions> 
237601 ········</ocil:questionnaire> 
237602 ········<ocil:questionnaire·id="ocil:ssg-service_squid_disabled_ocil:questionnaire:1"> 
237603 ··········<ocil:title>Disable·Squid</ocil:title> 
237604 ··········<ocil:actions> 
237605 ············<ocil:test_action_ref>ocil:ssg-service_squid_disabled_action:testaction:1</ocil:test_action_ref> 
237606 ··········</ocil:actions> 
237607 ········</ocil:questionnaire> 
237608 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1"> 
237609 ··········<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title> 
237610 ··········<ocil:actions> 
237611 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref> 
237612 ··········</ocil:actions> 
237613 ········</ocil:questionnaire> 
237614 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1"> 
237615 ··········<ocil:title>Verify·Owner·on·cron.monthly</ocil:title> 
237616 ··········<ocil:actions> 
237617 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref> 
237618 ··········</ocil:actions> 
237619 ········</ocil:questionnaire> 
237620 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_ocil:questionnaire:1"> 
237621 ··········<ocil:title>Disable·Kernel·Parameter·for·IPv6·Forwarding</ocil:title> 
237622 ··········<ocil:actions> 
237623 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_action:testaction:1</ocil:test_action_ref> 
237624 ··········</ocil:actions> 
237625 ········</ocil:questionnaire> 
237626 ········<ocil:questionnaire·id="ocil:ssg-package_firewalld_installed_ocil:questionnaire:1"> 
237627 ··········<ocil:title>Install·firewalld·Package</ocil:title> 
237628 ··········<ocil:actions> 
237629 ············<ocil:test_action_ref>ocil:ssg-package_firewalld_installed_action:testaction:1</ocil:test_action_ref> 
237630 ··········</ocil:actions> 
237631 ········</ocil:questionnaire> 
237632 ········<ocil:questionnaire·id="ocil:ssg-libreswan_approved_tunnels_ocil:questionnaire:1"> 
237633 ··········<ocil:title>Verify·Any·Configured·IPSec·Tunnel·Connections</ocil:title> 
237634 ··········<ocil:actions> 
237635 ············<ocil:test_action_ref>ocil:ssg-libreswan_approved_tunnels_action:testaction:1</ocil:test_action_ref> 
237636 ··········</ocil:actions> 
237637 ········</ocil:questionnaire> 
237638 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1"> 
237639 ··········<ocil:title>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</ocil:title> 
237640 ··········<ocil:actions> 
237641 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1</ocil:test_action_ref> 
237642 ··········</ocil:actions> 
237643 ········</ocil:questionnaire> 
237644 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_banner_enabled_ocil:questionnaire:1"> 
237645 ··········<ocil:title>Enable·GNOME3·Login·Warning·Banner</ocil:title> 
237646 ··········<ocil:actions> 
237647 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_banner_enabled_action:testaction:1</ocil:test_action_ref> 
237648 ··········</ocil:actions> 
237649 ········</ocil:questionnaire> 
237650 ········<ocil:questionnaire·id="ocil:ssg-network_configure_name_resolution_ocil:questionnaire:1"> 
237651 ··········<ocil:title>Configure·Multiple·DNS·Servers·in·/etc/resolv.conf</ocil:title> 
237652 ··········<ocil:actions>237598 ··········<ocil:actions>
237653 ············<ocil:test_action_ref>ocil:ssg-network_configure_name_resolution_action:testaction:1</ocil:test_action_ref>237599 ············<ocil:test_action_ref>ocil:ssg-audit_rules_suid_privilege_function_action:testaction:1</ocil:test_action_ref>
237654 ··········</ocil:actions>237600 ··········</ocil:actions>
237655 ········</ocil:questionnaire>237601 ········</ocil:questionnaire>
237656 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_chrony_keys_ocil:questionnaire:1">237602 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_sudoers_ocil:questionnaire:1">
237657 ··········<ocil:title>Verify·Permissions·On·/etc/chrony.keys·File</ocil:title>237603 ··········<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions·-·/etc/sudoers</ocil:title>
237658 ··········<ocil:actions>237604 ··········<ocil:actions>
237659 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_chrony_keys_action:testaction:1</ocil:test_action_ref>237605 ············<ocil:test_action_ref>ocil:ssg-audit_rules_sudoers_action:testaction:1</ocil:test_action_ref>
237660 ··········</ocil:actions>237606 ··········</ocil:actions>
237661 ········</ocil:questionnaire>237607 ········</ocil:questionnaire>
237662 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
237663 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>237608 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1">
 237609 ··········<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv4·Interfaces</ocil:title>
237664 ··········<ocil:actions>237610 ··········<ocil:actions>
Max diff block lines reached; 1891462/1901170 bytes (99.49%) of diff not shown.
1.74 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ocil.xml
1.74 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ocil.xml
Ordering differences only
    
Offset 3, 12083 lines modifiedOffset 3, 12150 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_suid_privilege_function_ocil:questionnaire:1">
 11 ······<ocil:title>Record·Events·When·Privileged·Executables·Are·Run</ocil:title>
11 ······<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-service_squid_disabled_ocil:questionnaire:1"> 
17 ······<ocil:title>Disable·Squid</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-service_squid_disabled_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1"> 
23 ······<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1"> 
29 ······<ocil:title>Verify·Owner·on·cron.monthly</ocil:title> 
30 ······<ocil:actions> 
31 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref> 
32 ······</ocil:actions> 
33 ····</ocil:questionnaire> 
34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_ocil:questionnaire:1"> 
35 ······<ocil:title>Disable·Kernel·Parameter·for·IPv6·Forwarding</ocil:title> 
36 ······<ocil:actions> 
37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_action:testaction:1</ocil:test_action_ref> 
38 ······</ocil:actions> 
39 ····</ocil:questionnaire> 
40 ····<ocil:questionnaire·id="ocil:ssg-package_firewalld_installed_ocil:questionnaire:1"> 
41 ······<ocil:title>Install·firewalld·Package</ocil:title> 
42 ······<ocil:actions> 
43 ········<ocil:test_action_ref>ocil:ssg-package_firewalld_installed_action:testaction:1</ocil:test_action_ref> 
44 ······</ocil:actions> 
45 ····</ocil:questionnaire> 
46 ····<ocil:questionnaire·id="ocil:ssg-libreswan_approved_tunnels_ocil:questionnaire:1"> 
47 ······<ocil:title>Verify·Any·Configured·IPSec·Tunnel·Connections</ocil:title> 
48 ······<ocil:actions> 
49 ········<ocil:test_action_ref>ocil:ssg-libreswan_approved_tunnels_action:testaction:1</ocil:test_action_ref> 
50 ······</ocil:actions> 
51 ····</ocil:questionnaire> 
52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1"> 
53 ······<ocil:title>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</ocil:title> 
54 ······<ocil:actions> 
55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1</ocil:test_action_ref> 
56 ······</ocil:actions> 
57 ····</ocil:questionnaire> 
58 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_banner_enabled_ocil:questionnaire:1"> 
59 ······<ocil:title>Enable·GNOME3·Login·Warning·Banner</ocil:title> 
60 ······<ocil:actions> 
61 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_banner_enabled_action:testaction:1</ocil:test_action_ref> 
62 ······</ocil:actions> 
63 ····</ocil:questionnaire> 
64 ····<ocil:questionnaire·id="ocil:ssg-network_configure_name_resolution_ocil:questionnaire:1"> 
65 ······<ocil:title>Configure·Multiple·DNS·Servers·in·/etc/resolv.conf</ocil:title> 
66 ······<ocil:actions>12 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-network_configure_name_resolution_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_suid_privilege_function_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>14 ······</ocil:actions>
69 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_chrony_keys_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sudoers_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Permissions·On·/etc/chrony.keys·File</ocil:title>17 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions·-·/etc/sudoers</ocil:title>
72 ······<ocil:actions>18 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_chrony_keys_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sudoers_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>20 ······</ocil:actions>
75 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
77 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1">
 23 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv4·Interfaces</ocil:title>
78 ······<ocil:actions>24 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>26 ······</ocil:actions>
81 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_chsh_ocil:questionnaire:1">
83 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open</ocil:title>29 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·chsh</ocil:title>
84 ······<ocil:actions>30 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_chsh_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>32 ······</ocil:actions>
87 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sebool_auditadm_exec_content_ocil:questionnaire:1"> 
89 ······<ocil:title>Enable·the·auditadm_exec_content·SELinux·Boolean</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-package_iprutils_removed_ocil:questionnaire:1">
 35 ······<ocil:title>Uninstall·iprutils·Package</ocil:title>
90 ······<ocil:actions>36 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sebool_auditadm_exec_content_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-package_iprutils_removed_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>38 ······</ocil:actions>
93 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_renameat_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-accounts_tmout_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·renameat</ocil:title>41 ······<ocil:title>Set·Interactive·Session·Timeout</ocil:title>
96 ······<ocil:actions>42 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_renameat_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-accounts_tmout_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>44 ······</ocil:actions>
99 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_audit_nosuid_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-accounts_set_post_pw_existing_ocil:questionnaire:1">
101 ······<ocil:title>Add·nosuid·Option·to·/var/log/audit</ocil:title>47 ······<ocil:title>Set·existing·passwords·a·period·of·inactivity·before·they·been·locked</ocil:title>
102 ······<ocil:actions>48 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_nosuid_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-accounts_set_post_pw_existing_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>50 ······</ocil:actions>
105 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-service_sshd_enabled_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-package_nss-tools_installed_ocil:questionnaire:1">
107 ······<ocil:title>Enable·the·OpenSSH·Service</ocil:title>53 ······<ocil:title>Ensure·nss-tools·is·installed</ocil:title>
108 ······<ocil:actions>54 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-service_sshd_enabled_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-package_nss-tools_installed_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>56 ······</ocil:actions>
111 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1"> 
113 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-package_gdm_removed_ocil:questionnaire:1">
 59 ······<ocil:title>Remove·the·GDM·Package·Group</ocil:title>
114 ······<ocil:actions>60 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-package_gdm_removed_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>62 ······</ocil:actions>
117 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_max_life_existing_ocil:questionnaire:1"> 
119 ······<ocil:title>Set·Existing·Passwords·Maximum·Age</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">
 65 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>
120 ······<ocil:actions>66 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_existing_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>68 ······</ocil:actions>
123 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1">
Max diff block lines reached; 1809628/1819950 bytes (99.43%) of diff not shown.
2.19 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds.xml
2.19 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol7.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol7.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol7.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol7.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:7">30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:7">
31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·7</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·7</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml">oval:ssg-installed_OS_is_ol7:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml">oval:ssg-installed_OS_is_ol7:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-7"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-7"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·7</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·7</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Oracle·Linux·7.·It·is·a·rendering·of42 configuration·settings·for·Oracle·Linux·7.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 355, 25 lines modifiedOffset 355, 25 lines modified
355 ··········</cpe-lang:logical-test>355 ··········</cpe-lang:logical-test>
356 ········</cpe-lang:platform>356 ········</cpe-lang:platform>
357 ········<cpe-lang:platform·id="package_bash">357 ········<cpe-lang:platform·id="package_bash">
358 ··········<cpe-lang:logical-test·operator="AND"·negate="false">358 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
359 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>359 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
360 ··········</cpe-lang:logical-test>360 ··········</cpe-lang:logical-test>
361 ········</cpe-lang:platform>361 ········</cpe-lang:platform>
362 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
363 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
364 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
365 ··········</cpe-lang:logical-test> 
366 ········</cpe-lang:platform> 
367 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">362 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
368 ··········<cpe-lang:logical-test·operator="AND"·negate="false">363 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
369 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>364 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
370 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>365 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
371 ··········</cpe-lang:logical-test>366 ··········</cpe-lang:logical-test>
372 ········</cpe-lang:platform>367 ········</cpe-lang:platform>
 368 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 369 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 370 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 371 ··········</cpe-lang:logical-test>
 372 ········</cpe-lang:platform>
373 ········<cpe-lang:platform·id="not_s390x_arch">373 ········<cpe-lang:platform·id="not_s390x_arch">
374 ··········<cpe-lang:logical-test·operator="AND"·negate="false">374 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
375 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>375 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
376 ··········</cpe-lang:logical-test>376 ··········</cpe-lang:logical-test>
377 ········</cpe-lang:platform>377 ········</cpe-lang:platform>
378 ········<cpe-lang:platform·id="package_shadow-utils">378 ········<cpe-lang:platform·id="package_shadow-utils">
379 ··········<cpe-lang:logical-test·operator="AND"·negate="false">379 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 237865, 15 lines modifiedOffset 237865, 15 lines modified
237865 ··············<xccdf-1.2:check-content-ref·href="ssg-ol7-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>237865 ··············<xccdf-1.2:check-content-ref·href="ssg-ol7-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
237866 ············</xccdf-1.2:check>237866 ············</xccdf-1.2:check>
237867 ··········</xccdf-1.2:Rule>237867 ··········</xccdf-1.2:Rule>
237868 ········</xccdf-1.2:Group>237868 ········</xccdf-1.2:Group>
237869 ······</xccdf-1.2:Group>237869 ······</xccdf-1.2:Group>
237870 ····</xccdf-1.2:Benchmark>237870 ····</xccdf-1.2:Benchmark>
237871 ··</ds:component>237871 ··</ds:component>
237872 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-oval.xml"·timestamp="2025-02-28T20:08:00">237872 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-oval.xml"·timestamp="2025-03-01T22:08:00">
237873 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">237873 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
237874 ······<oval-def:generator>237874 ······<oval-def:generator>
237875 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>237875 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
237876 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>237876 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
237877 ········<oval:schema_version>5.11</oval:schema_version>237877 ········<oval:schema_version>5.11</oval:schema_version>
237878 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>237878 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
237879 ······</oval-def:generator>237879 ······</oval-def:generator>
Offset 286201, 15741 lines modifiedOffset 286201, 15013 lines modified
286201 ············</oval-def:arithmetic>286201 ············</oval-def:arithmetic>
286202 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>286202 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
286203 ··········</oval-def:arithmetic>286203 ··········</oval-def:arithmetic>
286204 ········</oval-def:local_variable>286204 ········</oval-def:local_variable>
286205 ······</oval-def:variables>286205 ······</oval-def:variables>
286206 ····</oval-def:oval_definitions>286206 ····</oval-def:oval_definitions>
286207 ··</ds:component>286207 ··</ds:component>
286208 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-ocil.xml"·timestamp="2025-02-28T20:08:00">286208 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-ocil.xml"·timestamp="2025-03-01T22:08:00">
286209 ····<ocil:ocil>286209 ····<ocil:ocil>
286210 ······<ocil:generator>286210 ······<ocil:generator>
286211 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>286211 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
286212 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>286212 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
286213 ········<ocil:schema_version>2.0</ocil:schema_version>286213 ········<ocil:schema_version>2.0</ocil:schema_version>
286214 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>286214 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
286215 ······</ocil:generator>286215 ······</ocil:generator>
286216 ······<ocil:questionnaires>286216 ······<ocil:questionnaires>
 286217 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_sgid_ocil:questionnaire:1">
 286218 ··········<ocil:title>Ensure·All·SGID·Executables·Are·Authorized</ocil:title>
286217 ········<ocil:questionnaire·id="ocil:ssg-package_setroubleshoot-server_removed_ocil:questionnaire:1"> 
286218 ··········<ocil:title>Uninstall·setroubleshoot-server·Package</ocil:title> 
286219 ··········<ocil:actions> 
286220 ············<ocil:test_action_ref>ocil:ssg-package_setroubleshoot-server_removed_action:testaction:1</ocil:test_action_ref> 
286221 ··········</ocil:actions> 
286222 ········</ocil:questionnaire> 
286223 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fremovexattr_ocil:questionnaire:1"> 
286224 ··········<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fremovexattr</ocil:title> 
286225 ··········<ocil:actions>286219 ··········<ocil:actions>
286226 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>286220 ············<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_sgid_action:testaction:1</ocil:test_action_ref>
286227 ··········</ocil:actions>286221 ··········</ocil:actions>
286228 ········</ocil:questionnaire>286222 ········</ocil:questionnaire>
286229 ········<ocil:questionnaire·id="ocil:ssg-package_tftp-server_removed_ocil:questionnaire:1">286223 ········<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">
286230 ··········<ocil:title>Uninstall·tftp-server·Package</ocil:title>286224 ··········<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>
286231 ··········<ocil:actions>286225 ··········<ocil:actions>
286232 ············<ocil:test_action_ref>ocil:ssg-package_tftp-server_removed_action:testaction:1</ocil:test_action_ref>286226 ············<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>
286233 ··········</ocil:actions>286227 ··········</ocil:actions>
286234 ········</ocil:questionnaire>286228 ········</ocil:questionnaire>
286235 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1"> 
286236 ··········<ocil:title>Disable·kernel·debugfs</ocil:title>286229 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_ftruncate_ocil:questionnaire:1">
 286230 ··········<ocil:title>Record·Successful·Access·Attempts·to·Files·-·ftruncate</ocil:title>
286237 ··········<ocil:actions>286231 ··········<ocil:actions>
286238 ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>286232 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>
286239 ··········</ocil:actions>286233 ··········</ocil:actions>
286240 ········</ocil:questionnaire>286234 ········</ocil:questionnaire>
286241 ········<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1">286235 ········<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1">
286242 ··········<ocil:title>Disable·the·Automounter</ocil:title>286236 ··········<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>
286243 ··········<ocil:actions>286237 ··········<ocil:actions>
286244 ············<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref>286238 ············<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>
286245 ··········</ocil:actions>286239 ··········</ocil:actions>
286246 ········</ocil:questionnaire>286240 ········</ocil:questionnaire>
286247 ········<ocil:questionnaire·id="ocil:ssg-sebool_selinuxuser_use_ssh_chroot_ocil:questionnaire:1"> 
286248 ··········<ocil:title>Disable·the·selinuxuser_use_ssh_chroot·SELinux·Boolean</ocil:title>286241 ········<ocil:questionnaire·id="ocil:ssg-mount_option_nodev_remote_filesystems_ocil:questionnaire:1">
 286242 ··········<ocil:title>Mount·Remote·Filesystems·with·nodev</ocil:title>
286249 ··········<ocil:actions>286243 ··········<ocil:actions>
286250 ············<ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_use_ssh_chroot_action:testaction:1</ocil:test_action_ref>286244 ············<ocil:test_action_ref>ocil:ssg-mount_option_nodev_remote_filesystems_action:testaction:1</ocil:test_action_ref>
286251 ··········</ocil:actions>286245 ··········</ocil:actions>
286252 ········</ocil:questionnaire>286246 ········</ocil:questionnaire>
Max diff block lines reached; 2286958/2297755 bytes (99.53%) of diff not shown.
2.1 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ocil.xml
2.1 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ocil.xml
Ordering differences only
    
Offset 3, 15732 lines modifiedOffset 3, 15004 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
 10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_sgid_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·All·SGID·Executables·Are·Authorized</ocil:title>
10 ····<ocil:questionnaire·id="ocil:ssg-package_setroubleshoot-server_removed_ocil:questionnaire:1"> 
11 ······<ocil:title>Uninstall·setroubleshoot-server·Package</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-package_setroubleshoot-server_removed_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fremovexattr_ocil:questionnaire:1"> 
17 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fremovexattr</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_sgid_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-package_tftp-server_removed_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">
23 ······<ocil:title>Uninstall·tftp-server·Package</ocil:title>17 ······<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-package_tftp-server_removed_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1"> 
29 ······<ocil:title>Disable·kernel·debugfs</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_ftruncate_ocil:questionnaire:1">
 23 ······<ocil:title>Record·Successful·Access·Attempts·to·Files·-·ftruncate</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1">
35 ······<ocil:title>Disable·the·Automounter</ocil:title>29 ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sebool_selinuxuser_use_ssh_chroot_ocil:questionnaire:1"> 
41 ······<ocil:title>Disable·the·selinuxuser_use_ssh_chroot·SELinux·Boolean</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-mount_option_nodev_remote_filesystems_ocil:questionnaire:1">
 35 ······<ocil:title>Mount·Remote·Filesystems·with·nodev</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_use_ssh_chroot_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-mount_option_nodev_remote_filesystems_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_suid_privilege_function_ocil:questionnaire:1"> 
47 ······<ocil:title>Record·Events·When·Privileged·Executables·Are·Run</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-service_chronyd_or_ntpd_enabled_ocil:questionnaire:1">
 41 ······<ocil:title>Enable·the·NTP·Daemon</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_suid_privilege_function_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-service_chronyd_or_ntpd_enabled_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_library_dirs_ocil:questionnaire:1"> 
53 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Restrictive·Permissions</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">
 47 ······<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-dir_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_issue_net_ocil:questionnaire:1"> 
59 ······<ocil:title>Verify·Group·Ownership·of·System·Login·Banner·for·Remote·Connections</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1">
 53 ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_net_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sshd_print_last_log_ocil:questionnaire:1">
65 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>59 ······<ocil:title>Enable·SSH·Print·Last·Log</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sshd_print_last_log_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-partition_for_boot_ocil:questionnaire:1"> 
71 ······<ocil:title>Ensure·/boot·Located·On·Separate·Partition</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_removexattr_ocil:questionnaire:1">
 65 ······<ocil:title>Record·Unsuccessful·Permission·Changes·to·Files·-·removexattr</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-partition_for_boot_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_removexattr_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-configure_firewalld_rate_limiting_ocil:questionnaire:1"> 
77 ······<ocil:title>Configure·firewalld·To·Rate·Limit·Connections</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-sebool_abrt_anon_write_ocil:questionnaire:1">
 71 ······<ocil:title>Disable·the·abrt_anon_write·SELinux·Boolean</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-configure_firewalld_rate_limiting_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sebool_abrt_anon_write_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_sudoers_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_local_packages_ocil:questionnaire:1">
83 ······<ocil:title>Verify·User·Who·Owns·/etc/sudoers·File</ocil:title>77 ······<ocil:title>Ensure·gpgcheck·Enabled·for·Local·Packages</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_sudoers_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_local_packages_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sudo_vdsm_nopasswd_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_shadow_ocil:questionnaire:1">
89 ······<ocil:title>Only·the·VDSM·User·Can·Use·sudo·NOPASSWD</ocil:title>83 ······<ocil:title>Verify·User·Who·Owns·shadow·File</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sudo_vdsm_nopasswd_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_shadow_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_passwd_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">
95 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/passwd</ocil:title>89 ······<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_passwd_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-service_syslogng_enabled_ocil:questionnaire:1"> 
101 ······<ocil:title>Enable·syslog-ng·Service</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1">
 95 ······<ocil:title>Ensure·Rsyslog·Authenticates·Off-Loaded·Audit·Records</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-service_syslogng_enabled_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_usrquota_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>101 ······<ocil:title>Add·usrquota·Option·to·/home</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_usrquota_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1"> 
113 ······<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_newuidmap_ocil:questionnaire:1">
 107 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·newuidmap</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_newuidmap_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-no_legacy_plus_entries_etc_passwd_ocil:questionnaire:1"> 
Max diff block lines reached; 2185819/2197991 bytes (99.45%) of diff not shown.
2.28 KB
./usr/share/xml/scap/ssg/content/ssg-ol7-xccdf.xml
2.18 KB
./usr/share/xml/scap/ssg/content/ssg-ol7-xccdf.xml
Ordering differences only
    
Offset 320, 25 lines modifiedOffset 320, 25 lines modified
320 ······</cpe-lang:logical-test>320 ······</cpe-lang:logical-test>
321 ····</cpe-lang:platform>321 ····</cpe-lang:platform>
322 ····<cpe-lang:platform·id="package_bash">322 ····<cpe-lang:platform·id="package_bash">
323 ······<cpe-lang:logical-test·operator="AND"·negate="false">323 ······<cpe-lang:logical-test·operator="AND"·negate="false">
324 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>324 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
325 ······</cpe-lang:logical-test>325 ······</cpe-lang:logical-test>
326 ····</cpe-lang:platform>326 ····</cpe-lang:platform>
327 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
328 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
329 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
330 ······</cpe-lang:logical-test> 
331 ····</cpe-lang:platform> 
332 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">327 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
333 ······<cpe-lang:logical-test·operator="AND"·negate="false">328 ······<cpe-lang:logical-test·operator="AND"·negate="false">
334 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>329 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
335 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>330 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
336 ······</cpe-lang:logical-test>331 ······</cpe-lang:logical-test>
337 ····</cpe-lang:platform>332 ····</cpe-lang:platform>
 333 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 334 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 335 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 336 ······</cpe-lang:logical-test>
 337 ····</cpe-lang:platform>
338 ····<cpe-lang:platform·id="not_s390x_arch">338 ····<cpe-lang:platform·id="not_s390x_arch">
339 ······<cpe-lang:logical-test·operator="AND"·negate="false">339 ······<cpe-lang:logical-test·operator="AND"·negate="false">
340 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>340 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
341 ······</cpe-lang:logical-test>341 ······</cpe-lang:logical-test>
342 ····</cpe-lang:platform>342 ····</cpe-lang:platform>
343 ····<cpe-lang:platform·id="package_shadow-utils">343 ····<cpe-lang:platform·id="package_shadow-utils">
344 ······<cpe-lang:logical-test·operator="AND"·negate="false">344 ······<cpe-lang:logical-test·operator="AND"·negate="false">
2.59 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds.xml
2.59 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol8.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol8.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol8.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol8.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:8">30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:8">
31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·8</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·8</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml">oval:ssg-installed_OS_is_ol8:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml">oval:ssg-installed_OS_is_ol8:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·8</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·8</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Oracle·Linux·8.·It·is·a·rendering·of42 configuration·settings·for·Oracle·Linux·8.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 264643, 15 lines modifiedOffset 264643, 15 lines modified
264643 ··············<xccdf-1.2:check-content-ref·href="ssg-ol8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>264643 ··············<xccdf-1.2:check-content-ref·href="ssg-ol8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
264644 ············</xccdf-1.2:check>264644 ············</xccdf-1.2:check>
264645 ··········</xccdf-1.2:Rule>264645 ··········</xccdf-1.2:Rule>
264646 ········</xccdf-1.2:Group>264646 ········</xccdf-1.2:Group>
264647 ······</xccdf-1.2:Group>264647 ······</xccdf-1.2:Group>
264648 ····</xccdf-1.2:Benchmark>264648 ····</xccdf-1.2:Benchmark>
264649 ··</ds:component>264649 ··</ds:component>
264650 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-oval.xml"·timestamp="2025-02-28T20:08:00">264650 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-oval.xml"·timestamp="2025-03-01T22:08:00">
264651 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">264651 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
264652 ······<oval-def:generator>264652 ······<oval-def:generator>
264653 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>264653 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
264654 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>264654 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
264655 ········<oval:schema_version>5.11</oval:schema_version>264655 ········<oval:schema_version>5.11</oval:schema_version>
264656 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>264656 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
264657 ······</oval-def:generator>264657 ······</oval-def:generator>
Offset 321125, 9801 lines modifiedOffset 321125, 9801 lines modified
321125 ············</oval-def:arithmetic>321125 ············</oval-def:arithmetic>
321126 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>321126 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
321127 ··········</oval-def:arithmetic>321127 ··········</oval-def:arithmetic>
321128 ········</oval-def:local_variable>321128 ········</oval-def:local_variable>
321129 ······</oval-def:variables>321129 ······</oval-def:variables>
321130 ····</oval-def:oval_definitions>321130 ····</oval-def:oval_definitions>
321131 ··</ds:component>321131 ··</ds:component>
321132 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-ocil.xml"·timestamp="2025-02-28T20:08:00">321132 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-ocil.xml"·timestamp="2025-03-01T22:08:00">
321133 ····<ocil:ocil>321133 ····<ocil:ocil>
321134 ······<ocil:generator>321134 ······<ocil:generator>
321135 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>321135 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
321136 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>321136 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
321137 ········<ocil:schema_version>2.0</ocil:schema_version>321137 ········<ocil:schema_version>2.0</ocil:schema_version>
321138 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>321138 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
321139 ······</ocil:generator>321139 ······</ocil:generator>
321140 ······<ocil:questionnaires>321140 ······<ocil:questionnaires>
321141 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1"> 
321142 ··········<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>321141 ········<ocil:questionnaire·id="ocil:ssg-package_python3-abrt-addon_removed_ocil:questionnaire:1">
 321142 ··········<ocil:title>Uninstall·python3-abrt-addon·Package</ocil:title>
321143 ··········<ocil:actions>321143 ··········<ocil:actions>
321144 ············<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>321144 ············<ocil:test_action_ref>ocil:ssg-package_python3-abrt-addon_removed_action:testaction:1</ocil:test_action_ref>
321145 ··········</ocil:actions>321145 ··········</ocil:actions>
321146 ········</ocil:questionnaire>321146 ········</ocil:questionnaire>
321147 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_setfacl_ocil:questionnaire:1">321147 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">
321148 ··········<ocil:title>Record·Any·Attempts·to·Run·setfacl</ocil:title>321148 ··········<ocil:title>Verify·Owner·on·cron.monthly</ocil:title>
321149 ··········<ocil:actions>321149 ··········<ocil:actions>
321150 ············<ocil:test_action_ref>ocil:ssg-audit_rules_execution_setfacl_action:testaction:1</ocil:test_action_ref>321150 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>
321151 ··········</ocil:actions>321151 ··········</ocil:actions>
321152 ········</ocil:questionnaire>321152 ········</ocil:questionnaire>
321153 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlinkat_ocil:questionnaire:1"> 
321154 ··········<ocil:title>Record·Unsuccessful·Delete·Attempts·to·Files·-·unlinkat</ocil:title>321153 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1">
 321154 ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>
321155 ··········<ocil:actions>321155 ··········<ocil:actions>
321156 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_unlinkat_action:testaction:1</ocil:test_action_ref>321156 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>
321157 ··········</ocil:actions>321157 ··········</ocil:actions>
321158 ········</ocil:questionnaire>321158 ········</ocil:questionnaire>
321159 ········<ocil:questionnaire·id="ocil:ssg-sebool_xguest_exec_content_ocil:questionnaire:1">321159 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1">
321160 ··········<ocil:title>Disable·the·xguest_exec_content·SELinux·Boolean</ocil:title>321160 ··········<ocil:title>Configure·audit·according·to·OSPP·requirements</ocil:title>
321161 ··········<ocil:actions>321161 ··········<ocil:actions>
321162 ············<ocil:test_action_ref>ocil:ssg-sebool_xguest_exec_content_action:testaction:1</ocil:test_action_ref>321162 ············<ocil:test_action_ref>ocil:ssg-audit_rules_for_ospp_action:testaction:1</ocil:test_action_ref>
321163 ··········</ocil:actions>321163 ··········</ocil:actions>
321164 ········</ocil:questionnaire>321164 ········</ocil:questionnaire>
321165 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1">321165 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_wifi_notification_ocil:questionnaire:1">
321166 ··········<ocil:title>Disable·the·IPv6·protocol</ocil:title>321166 ··········<ocil:title>Disable·WIFI·Network·Notification·in·GNOME3</ocil:title>
321167 ··········<ocil:actions>321167 ··········<ocil:actions>
321168 ············<ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref>321168 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_wifi_notification_action:testaction:1</ocil:test_action_ref>
321169 ··········</ocil:actions>321169 ··········</ocil:actions>
321170 ········</ocil:questionnaire>321170 ········</ocil:questionnaire>
321171 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_files_ownership_ocil:questionnaire:1">321171 ········<ocil:questionnaire·id="ocil:ssg-xwindows_remove_packages_ocil:questionnaire:1">
321172 ··········<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·User</ocil:title>321172 ··········<ocil:title>Disable·graphical·user·interface</ocil:title>
321173 ··········<ocil:actions>321173 ··········<ocil:actions>
321174 ············<ocil:test_action_ref>ocil:ssg-rsyslog_files_ownership_action:testaction:1</ocil:test_action_ref>321174 ············<ocil:test_action_ref>ocil:ssg-xwindows_remove_packages_action:testaction:1</ocil:test_action_ref>
321175 ··········</ocil:actions>321175 ··········</ocil:actions>
321176 ········</ocil:questionnaire>321176 ········</ocil:questionnaire>
321177 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fsetxattr_ocil:questionnaire:1"> 
321178 ··········<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fsetxattr</ocil:title>321177 ········<ocil:questionnaire·id="ocil:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy_ocil:questionnaire:1">
 321178 ··········<ocil:title>Configure·SSH·Client·to·Use·FIPS·140·Validated·Ciphers:·openssh.config</ocil:title>
321179 ··········<ocil:actions>321179 ··········<ocil:actions>
321180 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fsetxattr_action:testaction:1</ocil:test_action_ref>321180 ············<ocil:test_action_ref>ocil:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy_action:testaction:1</ocil:test_action_ref>
321181 ··········</ocil:actions>321181 ··········</ocil:actions>
321182 ········</ocil:questionnaire>321182 ········</ocil:questionnaire>
321183 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_rule_order_ocil:questionnaire:1"> 
321184 ··········<ocil:title>Ensure·auditd·Rules·For·Unauthorized·Attempts·To·openat·Are·Ordered·Correctly</ocil:title>321183 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1">
 321184 ··········<ocil:title>Configure·ARP·filtering·for·All·IPv4·Interfaces</ocil:title>
321185 ··········<ocil:actions>321185 ··········<ocil:actions>
321186 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_rule_order_action:testaction:1</ocil:test_action_ref>321186 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1</ocil:test_action_ref>
321187 ··········</ocil:actions>321187 ··········</ocil:actions>
321188 ········</ocil:questionnaire>321188 ········</ocil:questionnaire>
321189 ········<ocil:questionnaire·id="ocil:ssg-account_password_selinux_faillock_dir_ocil:questionnaire:1"> 
321190 ··········<ocil:title>An·SELinux·Context·must·be·configured·for·the·pam_faillock.so·records·directory</ocil:title>321189 ········<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_ocil:questionnaire:1">
 321190 ··········<ocil:title>Configure·System·to·Forward·All·Mail·From·Postmaster·to·The·Root·Account</ocil:title>
321191 ··········<ocil:actions>321191 ··········<ocil:actions>
321192 ············<ocil:test_action_ref>ocil:ssg-account_password_selinux_faillock_dir_action:testaction:1</ocil:test_action_ref>321192 ············<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_postmaster_action:testaction:1</ocil:test_action_ref>
321193 ··········</ocil:actions>321193 ··········</ocil:actions>
321194 ········</ocil:questionnaire>321194 ········</ocil:questionnaire>
321195 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_truncate_ocil:questionnaire:1"> 
321196 ··········<ocil:title>Record·Successful·Access·Attempts·to·Files·-·truncate</ocil:title>321195 ········<ocil:questionnaire·id="ocil:ssg-package_sssd_installed_ocil:questionnaire:1">
 321196 ··········<ocil:title>Install·the·SSSD·Package</ocil:title>
321197 ··········<ocil:actions>321197 ··········<ocil:actions>
321198 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_truncate_action:testaction:1</ocil:test_action_ref>321198 ············<ocil:test_action_ref>ocil:ssg-package_sssd_installed_action:testaction:1</ocil:test_action_ref>
321199 ··········</ocil:actions>321199 ··········</ocil:actions>
321200 ········</ocil:questionnaire>321200 ········</ocil:questionnaire>
321201 ········<ocil:questionnaire·id="ocil:ssg-sebool_selinuxuser_execmod_ocil:questionnaire:1">321201 ········<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1">
321202 ··········<ocil:title>Enable·the·selinuxuser_execmod·SELinux·Boolean</ocil:title>321202 ··········<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title>
321203 ··········<ocil:actions>321203 ··········<ocil:actions>
321204 ············<ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_execmod_action:testaction:1</ocil:test_action_ref>321204 ············<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref>
321205 ··········</ocil:actions>321205 ··········</ocil:actions>
Max diff block lines reached; 2699113/2711288 bytes (99.55%) of diff not shown.
2.48 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ocil.xml
2.48 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ocil.xml
Ordering differences only
    
Offset 3, 9792 lines modifiedOffset 3, 9792 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-package_python3-abrt-addon_removed_ocil:questionnaire:1">
 11 ······<ocil:title>Uninstall·python3-abrt-addon·Package</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-package_python3-abrt-addon_removed_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_setfacl_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">
17 ······<ocil:title>Record·Any·Attempts·to·Run·setfacl</ocil:title>17 ······<ocil:title>Verify·Owner·on·cron.monthly</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_setfacl_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlinkat_ocil:questionnaire:1"> 
23 ······<ocil:title>Record·Unsuccessful·Delete·Attempts·to·Files·-·unlinkat</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1">
 23 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_unlinkat_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sebool_xguest_exec_content_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1">
29 ······<ocil:title>Disable·the·xguest_exec_content·SELinux·Boolean</ocil:title>29 ······<ocil:title>Configure·audit·according·to·OSPP·requirements</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sebool_xguest_exec_content_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_for_ospp_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_wifi_notification_ocil:questionnaire:1">
35 ······<ocil:title>Disable·the·IPv6·protocol</ocil:title>35 ······<ocil:title>Disable·WIFI·Network·Notification·in·GNOME3</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_wifi_notification_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_ownership_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-xwindows_remove_packages_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·User</ocil:title>41 ······<ocil:title>Disable·graphical·user·interface</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_ownership_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-xwindows_remove_packages_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fsetxattr_ocil:questionnaire:1"> 
47 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fsetxattr</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy_ocil:questionnaire:1">
 47 ······<ocil:title>Configure·SSH·Client·to·Use·FIPS·140·Validated·Ciphers:·openssh.config</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fsetxattr_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_rule_order_ocil:questionnaire:1"> 
53 ······<ocil:title>Ensure·auditd·Rules·For·Unauthorized·Attempts·To·openat·Are·Ordered·Correctly</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1">
 53 ······<ocil:title>Configure·ARP·filtering·for·All·IPv4·Interfaces</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_rule_order_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-account_password_selinux_faillock_dir_ocil:questionnaire:1"> 
59 ······<ocil:title>An·SELinux·Context·must·be·configured·for·the·pam_faillock.so·records·directory</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_ocil:questionnaire:1">
 59 ······<ocil:title>Configure·System·to·Forward·All·Mail·From·Postmaster·to·The·Root·Account</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-account_password_selinux_faillock_dir_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_postmaster_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_truncate_ocil:questionnaire:1"> 
65 ······<ocil:title>Record·Successful·Access·Attempts·to·Files·-·truncate</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-package_sssd_installed_ocil:questionnaire:1">
 65 ······<ocil:title>Install·the·SSSD·Package</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_truncate_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-package_sssd_installed_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sebool_selinuxuser_execmod_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1">
71 ······<ocil:title>Enable·the·selinuxuser_execmod·SELinux·Boolean</ocil:title>71 ······<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_execmod_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_hourly_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_setfacl_ocil:questionnaire:1">
77 ······<ocil:title>Verify·Permissions·on·cron.hourly</ocil:title>77 ······<ocil:title>Record·Any·Attempts·to·Run·setfacl</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_hourly_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_setfacl_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_ipsec_conf_ocil:questionnaire:1"> 
83 ······<ocil:title>Verify·Permissions·On·/etc/ipsec.conf·File</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_unix_update_ocil:questionnaire:1">
 83 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·unix_update</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_ipsec_conf_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_unix_update_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1">
89 ······<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title>89 ······<ocil:title>Disable·GSSAPI·Authentication</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_gssapi_auth_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_creat_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ssh_keysign_ocil:questionnaire:1">
95 ······<ocil:title>Record·Successful·Access·Attempts·to·Files·-·creat</ocil:title>95 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·ssh-keysign</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_creat_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_ssh_keysign_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fchownat_ocil:questionnaire:1"> 
101 ······<ocil:title>Record·Successful·Ownership·Changes·to·Files·-·fchownat</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-service_chronyd_or_ntpd_enabled_ocil:questionnaire:1">
 101 ······<ocil:title>Enable·the·NTP·Daemon</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fchownat_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-service_chronyd_or_ntpd_enabled_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_audit_tools_permissions_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1">
107 ······<ocil:title>Audit·Tools·Must·Have·a·Mode·of·0755·or·Less·Permissive</ocil:title>107 ······<ocil:title>Verify·Permissions·on·crontab</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_audit_tools_permissions_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-partition_for_boot_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_config_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·/boot·Located·On·Separate·Partition</ocil:title>113 ······<ocil:title>Verify·Permissions·on·SSH·Server·config·file</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-partition_for_boot_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_config_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·auditd·Rules·For·Unauthorized·Attempts·To·open·Are·Ordered·Correctly</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
 119 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
Max diff block lines reached; 2586275/2599228 bytes (99.50%) of diff not shown.
2.06 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds.xml
2.06 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol9.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol9.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol9.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol9.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:9">30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:9">
31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·9</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·9</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml">oval:ssg-installed_OS_is_ol9:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml">oval:ssg-installed_OS_is_ol9:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·9</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·9</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Oracle·Linux·9.·It·is·a·rendering·of42 configuration·settings·for·Oracle·Linux·9.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 370, 23 lines modifiedOffset 370, 23 lines modified
370 ··········</cpe-lang:logical-test>370 ··········</cpe-lang:logical-test>
371 ········</cpe-lang:platform>371 ········</cpe-lang:platform>
372 ········<cpe-lang:platform·id="package_bash">372 ········<cpe-lang:platform·id="package_bash">
373 ··········<cpe-lang:logical-test·operator="AND"·negate="false">373 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
374 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>374 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
375 ··········</cpe-lang:logical-test>375 ··········</cpe-lang:logical-test>
376 ········</cpe-lang:platform>376 ········</cpe-lang:platform>
377 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">377 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
378 ··········<cpe-lang:logical-test·operator="AND"·negate="false">378 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
379 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>379 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
380 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
381 ··········</cpe-lang:logical-test>380 ··········</cpe-lang:logical-test>
382 ········</cpe-lang:platform>381 ········</cpe-lang:platform>
383 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">382 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
384 ··········<cpe-lang:logical-test·operator="AND"·negate="false">383 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
385 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>384 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 385 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
386 ··········</cpe-lang:logical-test>386 ··········</cpe-lang:logical-test>
387 ········</cpe-lang:platform>387 ········</cpe-lang:platform>
388 ········<cpe-lang:platform·id="not_s390x_arch">388 ········<cpe-lang:platform·id="not_s390x_arch">
389 ··········<cpe-lang:logical-test·operator="AND"·negate="false">389 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
390 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>390 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
391 ··········</cpe-lang:logical-test>391 ··········</cpe-lang:logical-test>
392 ········</cpe-lang:platform>392 ········</cpe-lang:platform>
Offset 204458, 15 lines modifiedOffset 204458, 15 lines modified
204458 ··············<xccdf-1.2:check-content-ref·href="ssg-ol9-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ocil:questionnaire:1"/>204458 ··············<xccdf-1.2:check-content-ref·href="ssg-ol9-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ocil:questionnaire:1"/>
204459 ············</xccdf-1.2:check>204459 ············</xccdf-1.2:check>
204460 ··········</xccdf-1.2:Rule>204460 ··········</xccdf-1.2:Rule>
204461 ········</xccdf-1.2:Group>204461 ········</xccdf-1.2:Group>
204462 ······</xccdf-1.2:Group>204462 ······</xccdf-1.2:Group>
204463 ····</xccdf-1.2:Benchmark>204463 ····</xccdf-1.2:Benchmark>
204464 ··</ds:component>204464 ··</ds:component>
204465 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-oval.xml"·timestamp="2025-02-28T20:08:00">204465 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-oval.xml"·timestamp="2025-03-01T22:08:00">
204466 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">204466 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
204467 ······<oval-def:generator>204467 ······<oval-def:generator>
204468 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>204468 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
204469 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>204469 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
204470 ········<oval:schema_version>5.11</oval:schema_version>204470 ········<oval:schema_version>5.11</oval:schema_version>
204471 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>204471 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
204472 ······</oval-def:generator>204472 ······</oval-def:generator>
Offset 250354, 15277 lines modifiedOffset 250354, 15731 lines modified
250354 ············</oval-def:arithmetic>250354 ············</oval-def:arithmetic>
250355 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>250355 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
250356 ··········</oval-def:arithmetic>250356 ··········</oval-def:arithmetic>
250357 ········</oval-def:local_variable>250357 ········</oval-def:local_variable>
250358 ······</oval-def:variables>250358 ······</oval-def:variables>
250359 ····</oval-def:oval_definitions>250359 ····</oval-def:oval_definitions>
250360 ··</ds:component>250360 ··</ds:component>
250361 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-ocil.xml"·timestamp="2025-02-28T20:08:00">250361 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-ocil.xml"·timestamp="2025-03-01T22:08:00">
250362 ····<ocil:ocil>250362 ····<ocil:ocil>
250363 ······<ocil:generator>250363 ······<ocil:generator>
250364 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>250364 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
250365 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>250365 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
250366 ········<ocil:schema_version>2.0</ocil:schema_version>250366 ········<ocil:schema_version>2.0</ocil:schema_version>
250367 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>250367 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
250368 ······</ocil:generator>250368 ······</ocil:generator>
250369 ······<ocil:questionnaires>250369 ······<ocil:questionnaires>
250370 ········<ocil:questionnaire·id="ocil:ssg-use_pam_wheel_for_su_ocil:questionnaire:1">250370 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_ip_forward_ocil:questionnaire:1">
 250371 ··········<ocil:title>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</ocil:title>
250371 ··········<ocil:title>Enforce·usage·of·pam_wheel·for·su·authentication</ocil:title> 
250372 ··········<ocil:actions> 
250373 ············<ocil:test_action_ref>ocil:ssg-use_pam_wheel_for_su_action:testaction:1</ocil:test_action_ref> 
250374 ··········</ocil:actions> 
250375 ········</ocil:questionnaire> 
250376 ········<ocil:questionnaire·id="ocil:ssg-aide_scan_notification_ocil:questionnaire:1"> 
250377 ··········<ocil:title>Configure·Notification·of·Post-AIDE·Scan·Details</ocil:title> 
250378 ··········<ocil:actions>250372 ··········<ocil:actions>
250379 ············<ocil:test_action_ref>ocil:ssg-aide_scan_notification_action:testaction:1</ocil:test_action_ref>250373 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_forward_action:testaction:1</ocil:test_action_ref>
250380 ··········</ocil:actions>250374 ··········</ocil:actions>
250381 ········</ocil:questionnaire>250375 ········</ocil:questionnaire>
250382 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_sudoedit_ocil:questionnaire:1"> 
250383 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·sudoedit</ocil:title>250376 ········<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_no_world_writable_programs_ocil:questionnaire:1">
 250377 ··········<ocil:title>User·Initialization·Files·Must·Not·Run·World-Writable·Programs</ocil:title>
250384 ··········<ocil:actions>250378 ··········<ocil:actions>
250385 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_sudoedit_action:testaction:1</ocil:test_action_ref>250379 ············<ocil:test_action_ref>ocil:ssg-accounts_user_dot_no_world_writable_programs_action:testaction:1</ocil:test_action_ref>
250386 ··········</ocil:actions>250380 ··········</ocil:actions>
250387 ········</ocil:questionnaire>250381 ········</ocil:questionnaire>
250388 ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_audit_nodev_ocil:questionnaire:1"> 
250389 ··········<ocil:title>Add·nodev·Option·to·/var/log/audit</ocil:title>250382 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_modules_disabled_ocil:questionnaire:1">
 250383 ··········<ocil:title>Disable·loading·and·unloading·of·kernel·modules</ocil:title>
250390 ··········<ocil:actions>250384 ··········<ocil:actions>
250391 ············<ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_nodev_action:testaction:1</ocil:test_action_ref>250385 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_modules_disabled_action:testaction:1</ocil:test_action_ref>
250392 ··········</ocil:actions>250386 ··········</ocil:actions>
250393 ········</ocil:questionnaire>250387 ········</ocil:questionnaire>
250394 ········<ocil:questionnaire·id="ocil:ssg-require_singleuser_auth_ocil:questionnaire:1">250388 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">
250395 ··········<ocil:title>Require·Authentication·for·Single·User·Mode</ocil:title>250389 ··········<ocil:title>Enable·support·for·BUG()</ocil:title>
250396 ··········<ocil:actions>250390 ··········<ocil:actions>
250397 ············<ocil:test_action_ref>ocil:ssg-require_singleuser_auth_action:testaction:1</ocil:test_action_ref>250391 ············<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref>
250398 ··········</ocil:actions>250392 ··········</ocil:actions>
250399 ········</ocil:questionnaire>250393 ········</ocil:questionnaire>
250400 ········<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_forward_ocil:questionnaire:1">250394 ········<ocil:questionnaire·id="ocil:ssg-network_sniffer_disabled_ocil:questionnaire:1">
250401 ··········<ocil:title>Set·Default·iptables·Policy·for·Forwarded·Packets</ocil:title>250395 ··········<ocil:title>Ensure·System·is·Not·Acting·as·a·Network·Sniffer</ocil:title>
250402 ··········<ocil:actions>250396 ··········<ocil:actions>
250403 ············<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_forward_action:testaction:1</ocil:test_action_ref>250397 ············<ocil:test_action_ref>ocil:ssg-network_sniffer_disabled_action:testaction:1</ocil:test_action_ref>
250404 ··········</ocil:actions>250398 ··········</ocil:actions>
250405 ········</ocil:questionnaire>250399 ········</ocil:questionnaire>
250406 ········<ocil:questionnaire·id="ocil:ssg-account_unique_id_ocil:questionnaire:1"> 
250407 ··········<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·User·IDs</ocil:title>250400 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_ocil:questionnaire:1">
 250401 ··········<ocil:title>Configure·Accepting·Router·Preference·in·Router·Advertisements·on·All·IPv6·Interfaces</ocil:title>
250408 ··········<ocil:actions>250402 ··········<ocil:actions>
250409 ············<ocil:test_action_ref>ocil:ssg-account_unique_id_action:testaction:1</ocil:test_action_ref>250403 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_action:testaction:1</ocil:test_action_ref>
250410 ··········</ocil:actions>250404 ··········</ocil:actions>
250411 ········</ocil:questionnaire>250405 ········</ocil:questionnaire>
Max diff block lines reached; 2149916/2161641 bytes (99.46%) of diff not shown.
1.97 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ocil.xml
1.97 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ocil.xml
Ordering differences only
    
Offset 3, 15268 lines modifiedOffset 3, 15722 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-use_pam_wheel_for_su_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_ip_forward_ocil:questionnaire:1">
 11 ······<ocil:title>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</ocil:title>
11 ······<ocil:title>Enforce·usage·of·pam_wheel·for·su·authentication</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-use_pam_wheel_for_su_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-aide_scan_notification_ocil:questionnaire:1"> 
17 ······<ocil:title>Configure·Notification·of·Post-AIDE·Scan·Details</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-aide_scan_notification_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_forward_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_sudoedit_ocil:questionnaire:1"> 
23 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·sudoedit</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_no_world_writable_programs_ocil:questionnaire:1">
 17 ······<ocil:title>User·Initialization·Files·Must·Not·Run·World-Writable·Programs</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_sudoedit_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-accounts_user_dot_no_world_writable_programs_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_audit_nodev_ocil:questionnaire:1"> 
29 ······<ocil:title>Add·nodev·Option·to·/var/log/audit</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_modules_disabled_ocil:questionnaire:1">
 23 ······<ocil:title>Disable·loading·and·unloading·of·kernel·modules</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_nodev_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_modules_disabled_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-require_singleuser_auth_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">
35 ······<ocil:title>Require·Authentication·for·Single·User·Mode</ocil:title>29 ······<ocil:title>Enable·support·for·BUG()</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-require_singleuser_auth_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_forward_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-network_sniffer_disabled_ocil:questionnaire:1">
41 ······<ocil:title>Set·Default·iptables·Policy·for·Forwarded·Packets</ocil:title>35 ······<ocil:title>Ensure·System·is·Not·Acting·as·a·Network·Sniffer</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_forward_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-network_sniffer_disabled_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-account_unique_id_ocil:questionnaire:1"> 
47 ······<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·User·IDs</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_ocil:questionnaire:1">
 41 ······<ocil:title>Configure·Accepting·Router·Preference·in·Router·Advertisements·on·All·IPv6·Interfaces</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-account_unique_id_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_su_ocil:questionnaire:1"> 
53 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·su</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-directory_access_var_log_audit_ocil:questionnaire:1">
 47 ······<ocil:title>Record·Access·Events·to·Audit·Log·Directory</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_su_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-directory_access_var_log_audit_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_core_uses_pid_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>53 ······<ocil:title>Configure·file·name·of·core·dumps</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_core_uses_pid_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_group_ocil:questionnaire:1"> 
65 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/group</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_etc_nftables_ocil:questionnaire:1">
 59 ······<ocil:title>Verify·Permissions·On·/etc/nftables·Directory</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_group_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_etc_nftables_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-ensure_oracle_gpgkey_installed_ocil:questionnaire:1"> 
71 ······<ocil:title>Ensure·Oracle·Linux·GPG·Key·Installed</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-accounts_users_home_files_ownership_ocil:questionnaire:1">
 65 ······<ocil:title>All·User·Files·and·Directories·In·The·Home·Directory·Must·Have·a·Valid·Owner</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-ensure_oracle_gpgkey_installed_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-accounts_users_home_files_ownership_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-service_debug-shell_disabled_ocil:questionnaire:1">
77 ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>71 ······<ocil:title>Disable·debug-shell·SystemD·Service</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-service_debug-shell_disabled_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-no_rsh_trust_files_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_private_key_ocil:questionnaire:1">
83 ······<ocil:title>Remove·Rsh·Trust·Files</ocil:title>77 ······<ocil:title>Verify·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-no_rsh_trust_files_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_modify_success_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1">
89 ······<ocil:title>Configure·auditing·of·successful·file·modifications</ocil:title>83 ······<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_modify_success_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-aide_check_audit_tools_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-accounts_users_home_files_permissions_ocil:questionnaire:1">
95 ······<ocil:title>Configure·AIDE·to·Verify·the·Audit·Tools</ocil:title>89 ······<ocil:title>All·User·Files·and·Directories·In·The·Home·Directory·Must·Have·Mode·0750·Or·Less·Permissive</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-aide_check_audit_tools_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-accounts_users_home_files_permissions_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sudoers_validate_passwd_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·invoking·users·password·for·privilege·escalation·when·using·sudo</ocil:title>95 ······<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sudoers_validate_passwd_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-aide_verify_acls_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">
107 ······<ocil:title>Configure·AIDE·to·Verify·Access·Control·Lists·(ACLs)</ocil:title>101 ······<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-aide_verify_acls_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_interactive_home_directory_defined_ocil:questionnaire:1"> 
113 ······<ocil:title>All·Interactive·Users·Must·Have·A·Home·Directory·Defined</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_postqueue_ocil:questionnaire:1">
 107 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·postqueue</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-accounts_user_interactive_home_directory_defined_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_postqueue_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-configure_firewalld_ports_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-service_ufw_enabled_ocil:questionnaire:1">
119 ······<ocil:title>Configure·the·Firewalld·Ports</ocil:title>113 ······<ocil:title>Verify·ufw·Enabled</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-configure_firewalld_ports_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-service_ufw_enabled_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 2056153/2068436 bytes (99.41%) of diff not shown.
2.47 KB
./usr/share/xml/scap/ssg/content/ssg-ol9-xccdf.xml
2.37 KB
./usr/share/xml/scap/ssg/content/ssg-ol9-xccdf.xml
Ordering differences only
    
Offset 335, 23 lines modifiedOffset 335, 23 lines modified
335 ······</cpe-lang:logical-test>335 ······</cpe-lang:logical-test>
336 ····</cpe-lang:platform>336 ····</cpe-lang:platform>
337 ····<cpe-lang:platform·id="package_bash">337 ····<cpe-lang:platform·id="package_bash">
338 ······<cpe-lang:logical-test·operator="AND"·negate="false">338 ······<cpe-lang:logical-test·operator="AND"·negate="false">
339 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>339 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
340 ······</cpe-lang:logical-test>340 ······</cpe-lang:logical-test>
341 ····</cpe-lang:platform>341 ····</cpe-lang:platform>
342 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">342 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
343 ······<cpe-lang:logical-test·operator="AND"·negate="false">343 ······<cpe-lang:logical-test·operator="AND"·negate="false">
344 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>344 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
345 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
346 ······</cpe-lang:logical-test>345 ······</cpe-lang:logical-test>
347 ····</cpe-lang:platform>346 ····</cpe-lang:platform>
348 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">347 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
349 ······<cpe-lang:logical-test·operator="AND"·negate="false">348 ······<cpe-lang:logical-test·operator="AND"·negate="false">
350 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>349 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 350 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
351 ······</cpe-lang:logical-test>351 ······</cpe-lang:logical-test>
352 ····</cpe-lang:platform>352 ····</cpe-lang:platform>
353 ····<cpe-lang:platform·id="not_s390x_arch">353 ····<cpe-lang:platform·id="not_s390x_arch">
354 ······<cpe-lang:logical-test·operator="AND"·negate="false">354 ······<cpe-lang:logical-test·operator="AND"·negate="false">
355 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>355 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
356 ······</cpe-lang:logical-test>356 ······</cpe-lang:logical-test>
357 ····</cpe-lang:platform>357 ····</cpe-lang:platform>
940 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ds.xml
940 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:harden:">28 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:harden:">
29 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Harden·distribution</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Harden·distribution</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_oeharden:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_oeharden:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:nodistro:">32 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:nodistro:">
33 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·nodistro</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·nodistro</cpe-dict:title>
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:poky:">40 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:poky:">
41 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Poky·reference·distribution</cpe-dict:title>41 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Poky·reference·distribution</cpe-dict:title>
42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_poky:def:1</cpe-dict:check>42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_poky:def:1</cpe-dict:check>
43 ······</cpe-dict:cpe-item>43 ······</cpe-dict:cpe-item>
44 ····</cpe-dict:cpe-list>44 ····</cpe-dict:cpe-list>
45 ··</ds:component>45 ··</ds:component>
46 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-xccdf.xml"·timestamp="2025-02-28T20:08:00">46 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-xccdf.xml"·timestamp="2025-03-01T22:08:00">
47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEMBEDDED"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEMBEDDED"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·OpenEmbedded</xccdf-1.2:title>49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·OpenEmbedded</xccdf-1.2:title>
50 ······<xccdf-1.2:description>50 ······<xccdf-1.2:description>
51 ········This·guide·presents·a·catalog·of·security-relevant51 ········This·guide·presents·a·catalog·of·security-relevant
52 configuration·settings·for·OpenEmbedded.·It·is·a·rendering·of52 configuration·settings·for·OpenEmbedded.·It·is·a·rendering·of
53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 59078, 15 lines modifiedOffset 59078, 15 lines modified
59078 ··············<xccdf-1.2:check-content-ref·href="ssg-openembedded-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>59078 ··············<xccdf-1.2:check-content-ref·href="ssg-openembedded-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
59079 ············</xccdf-1.2:check>59079 ············</xccdf-1.2:check>
59080 ··········</xccdf-1.2:Rule>59080 ··········</xccdf-1.2:Rule>
59081 ········</xccdf-1.2:Group>59081 ········</xccdf-1.2:Group>
59082 ······</xccdf-1.2:Group>59082 ······</xccdf-1.2:Group>
59083 ····</xccdf-1.2:Benchmark>59083 ····</xccdf-1.2:Benchmark>
59084 ··</ds:component>59084 ··</ds:component>
59085 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-oval.xml"·timestamp="2025-02-28T20:08:00">59085 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-oval.xml"·timestamp="2025-03-01T22:08:00">
59086 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">59086 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
59087 ······<oval-def:generator>59087 ······<oval-def:generator>
59088 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>59088 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
59089 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>59089 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
59090 ········<oval:schema_version>5.11</oval:schema_version>59090 ········<oval:schema_version>5.11</oval:schema_version>
59091 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>59091 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
59092 ······</oval-def:generator>59092 ······</oval-def:generator>
Offset 81150, 2786 lines modifiedOffset 81150, 2786 lines modified
81150 ············</oval-def:arithmetic>81150 ············</oval-def:arithmetic>
81151 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>81151 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
81152 ··········</oval-def:arithmetic>81152 ··········</oval-def:arithmetic>
81153 ········</oval-def:local_variable>81153 ········</oval-def:local_variable>
81154 ······</oval-def:variables>81154 ······</oval-def:variables>
81155 ····</oval-def:oval_definitions>81155 ····</oval-def:oval_definitions>
81156 ··</ds:component>81156 ··</ds:component>
81157 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-ocil.xml"·timestamp="2025-02-28T20:08:00">81157 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-ocil.xml"·timestamp="2025-03-01T22:08:00">
81158 ····<ocil:ocil>81158 ····<ocil:ocil>
81159 ······<ocil:generator>81159 ······<ocil:generator>
81160 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>81160 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
81161 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>81161 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
81162 ········<ocil:schema_version>2.0</ocil:schema_version>81162 ········<ocil:schema_version>2.0</ocil:schema_version>
81163 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>81163 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
81164 ······</ocil:generator>81164 ······</ocil:generator>
81165 ······<ocil:questionnaires>81165 ······<ocil:questionnaires>
81166 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_files_permissions_ocil:questionnaire:1">81166 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">
81167 ··········<ocil:title>Ensure·System·Log·Files·Have·Correct·Permissions</ocil:title>81167 ··········<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>
81168 ··········<ocil:actions>81168 ··········<ocil:actions>
81169 ············<ocil:test_action_ref>ocil:ssg-rsyslog_files_permissions_action:testaction:1</ocil:test_action_ref>81169 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
81170 ··········</ocil:actions>81170 ··········</ocil:actions>
81171 ········</ocil:questionnaire>81171 ········</ocil:questionnaire>
81172 ········<ocil:questionnaire·id="ocil:ssg-dir_perms_world_writable_sticky_bits_ocil:questionnaire:1">81172 ········<ocil:questionnaire·id="ocil:ssg-service_snmpd_disabled_ocil:questionnaire:1">
81173 ··········<ocil:title>Verify·that·All·World-Writable·Directories·Have·Sticky·Bits·Set</ocil:title>81173 ··········<ocil:title>Disable·snmpd·Service</ocil:title>
81174 ··········<ocil:actions>81174 ··········<ocil:actions>
81175 ············<ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_sticky_bits_action:testaction:1</ocil:test_action_ref>81175 ············<ocil:test_action_ref>ocil:ssg-service_snmpd_disabled_action:testaction:1</ocil:test_action_ref>
81176 ··········</ocil:actions>81176 ··········</ocil:actions>
81177 ········</ocil:questionnaire>81177 ········</ocil:questionnaire>
81178 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1">81178 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1">
81179 ··········<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·by·Default</ocil:title>81179 ··········<ocil:title>Remove·the·kernel·mapping·in·user·mode</ocil:title>
81180 ··········<ocil:actions>81180 ··········<ocil:actions>
81181 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_action:testaction:1</ocil:test_action_ref>81181 ············<ocil:test_action_ref>ocil:ssg-kernel_config_page_table_isolation_action:testaction:1</ocil:test_action_ref>
81182 ··········</ocil:actions>81182 ··········</ocil:actions>
81183 ········</ocil:questionnaire>81183 ········</ocil:questionnaire>
81184 ········<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1">81184 ········<ocil:questionnaire·id="ocil:ssg-grub2_mce_argument_ocil:questionnaire:1">
81185 ··········<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title>81185 ··········<ocil:title>Force·kernel·panic·on·uncorrected·MCEs</ocil:title>
81186 ··········<ocil:actions>81186 ··········<ocil:actions>
81187 ············<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref>81187 ············<ocil:test_action_ref>ocil:ssg-grub2_mce_argument_action:testaction:1</ocil:test_action_ref>
81188 ··········</ocil:actions>81188 ··········</ocil:actions>
81189 ········</ocil:questionnaire>81189 ········</ocil:questionnaire>
81190 ········<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_dir_ocil:questionnaire:1">81190 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_gshadow_ocil:questionnaire:1">
81191 ··········<ocil:title>Account·Lockouts·Must·Persist</ocil:title>81191 ··········<ocil:title>Verify·User·Who·Owns·gshadow·File</ocil:title>
81192 ··········<ocil:actions>81192 ··········<ocil:actions>
81193 ············<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref>81193 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_gshadow_action:testaction:1</ocil:test_action_ref>
81194 ··········</ocil:actions>81194 ··········</ocil:actions>
81195 ········</ocil:questionnaire>81195 ········</ocil:questionnaire>
81196 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_hourly_ocil:questionnaire:1">81196 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_stig_ocil:questionnaire:1">
81197 ··········<ocil:title>Verify·Permissions·on·cron.hourly</ocil:title>81197 ··········<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>
81198 ··········<ocil:actions>81198 ··········<ocil:actions>
81199 ············<ocil:test_action_ref>ocil:ssg-file_permissions_cron_hourly_action:testaction:1</ocil:test_action_ref>81199 ············<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_stig_action:testaction:1</ocil:test_action_ref>
81200 ··········</ocil:actions>81200 ··········</ocil:actions>
81201 ········</ocil:questionnaire>81201 ········</ocil:questionnaire>
81202 ········<ocil:questionnaire·id="ocil:ssg-file_cron_deny_not_exist_ocil:questionnaire:1">81202 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">
81203 ··········<ocil:title>Ensure·that·/etc/cron.deny·does·not·exist</ocil:title>81203 ··········<ocil:title>Verify·Owner·on·cron.weekly</ocil:title>
81204 ··········<ocil:actions>81204 ··········<ocil:actions>
81205 ············<ocil:test_action_ref>ocil:ssg-file_cron_deny_not_exist_action:testaction:1</ocil:test_action_ref>81205 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>
81206 ··········</ocil:actions>81206 ··········</ocil:actions>
81207 ········</ocil:questionnaire>81207 ········</ocil:questionnaire>
81208 ········<ocil:questionnaire·id="ocil:ssg-service_smb_disabled_ocil:questionnaire:1">81208 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1">
81209 ··········<ocil:title>Disable·Samba</ocil:title>81209 ··········<ocil:title>Disable·IPv6·Addressing·on·All·IPv6·Interfaces</ocil:title>
81210 ··········<ocil:actions>81210 ··········<ocil:actions>
81211 ············<ocil:test_action_ref>ocil:ssg-service_smb_disabled_action:testaction:1</ocil:test_action_ref>81211 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_action:testaction:1</ocil:test_action_ref>
81212 ··········</ocil:actions>81212 ··········</ocil:actions>
81213 ········</ocil:questionnaire>81213 ········</ocil:questionnaire>
81214 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_ocil:questionnaire:1">81214 ········<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">
81215 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv4·Interfaces</ocil:title>81215 ··········<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>
81216 ··········<ocil:actions>81216 ··········<ocil:actions>
81217 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>81217 ············<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>
81218 ··········</ocil:actions>81218 ··········</ocil:actions>
81219 ········</ocil:questionnaire>81219 ········</ocil:questionnaire>
81220 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_set_min_life_existing_ocil:questionnaire:1">81220 ········<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_etc_shadow_ocil:questionnaire:1">
81221 ··········<ocil:title>Set·Existing·Passwords·Minimum·Age</ocil:title>81221 ··········<ocil:title>Ensure·There·Are·No·Accounts·With·Blank·or·Null·Passwords</ocil:title>
81222 ··········<ocil:actions>81222 ··········<ocil:actions>
81223 ············<ocil:test_action_ref>ocil:ssg-accounts_password_set_min_life_existing_action:testaction:1</ocil:test_action_ref>81223 ············<ocil:test_action_ref>ocil:ssg-no_empty_passwords_etc_shadow_action:testaction:1</ocil:test_action_ref>
81224 ··········</ocil:actions>81224 ··········</ocil:actions>
81225 ········</ocil:questionnaire>81225 ········</ocil:questionnaire>
81226 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">81226 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1">
81227 ··········<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>81227 ··········<ocil:title>Enable·checks·on·scatter-gather·(SG)·table·operations</ocil:title>
81228 ··········<ocil:actions>81228 ··········<ocil:actions>
Max diff block lines reached; 949893/962158 bytes (98.73%) of diff not shown.
896 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ocil.xml
895 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ocil.xml
Ordering differences only
    
Offset 3, 2777 lines modifiedOffset 3, 2777 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_permissions_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">
11 ······<ocil:title>Ensure·System·Log·Files·Have·Correct·Permissions</ocil:title>11 ······<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_permissions_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-dir_perms_world_writable_sticky_bits_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-service_snmpd_disabled_ocil:questionnaire:1">
17 ······<ocil:title>Verify·that·All·World-Writable·Directories·Have·Sticky·Bits·Set</ocil:title>17 ······<ocil:title>Disable·snmpd·Service</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_sticky_bits_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-service_snmpd_disabled_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1"> 
23 ······<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·by·Default</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1">
 23 ······<ocil:title>Remove·the·kernel·mapping·in·user·mode</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_table_isolation_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-grub2_mce_argument_ocil:questionnaire:1">
29 ······<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title>29 ······<ocil:title>Force·kernel·panic·on·uncorrected·MCEs</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-grub2_mce_argument_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_dir_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_gshadow_ocil:questionnaire:1">
35 ······<ocil:title>Account·Lockouts·Must·Persist</ocil:title>35 ······<ocil:title>Verify·User·Who·Owns·gshadow·File</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_gshadow_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_hourly_ocil:questionnaire:1"> 
41 ······<ocil:title>Verify·Permissions·on·cron.hourly</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_stig_ocil:questionnaire:1">
 41 ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_hourly_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_stig_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_cron_deny_not_exist_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·that·/etc/cron.deny·does·not·exist</ocil:title>47 ······<ocil:title>Verify·Owner·on·cron.weekly</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_cron_deny_not_exist_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-service_smb_disabled_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1">
53 ······<ocil:title>Disable·Samba</ocil:title>53 ······<ocil:title>Disable·IPv6·Addressing·on·All·IPv6·Interfaces</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-service_smb_disabled_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">
59 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv4·Interfaces</ocil:title>59 ······<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_min_life_existing_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_etc_shadow_ocil:questionnaire:1">
65 ······<ocil:title>Set·Existing·Passwords·Minimum·Age</ocil:title>65 ······<ocil:title>Ensure·There·Are·No·Accounts·With·Blank·or·Null·Passwords</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_min_life_existing_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-no_empty_passwords_etc_shadow_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>71 ······<ocil:title>Enable·checks·on·scatter-gather·(SG)·table·operations</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_sg_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_crontab_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_private_key_ocil:questionnaire:1">
77 ······<ocil:title>Verify·Group·Who·Owns·Crontab</ocil:title>77 ······<ocil:title>Verify·Group·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_crontab_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_minlen_login_defs_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-package_ntp_installed_ocil:questionnaire:1">
83 ······<ocil:title>Set·Password·Minimum·Length·in·login.defs</ocil:title>83 ······<ocil:title>Install·the·ntp·service</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-accounts_password_minlen_login_defs_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-package_ntp_installed_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_retpoline_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_group_ocil:questionnaire:1">
89 ······<ocil:title>Avoid·speculative·indirect·branches·in·kernel</ocil:title>89 ······<ocil:title>Verify·User·Who·Owns·Backup·group·File</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_retpoline_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"> 
95 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-require_singleuser_auth_ocil:questionnaire:1">
 95 ······<ocil:title>Require·Authentication·for·Single·User·Mode</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-require_singleuser_auth_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-accounts_maximum_age_login_defs_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1">
101 ······<ocil:title>Set·Password·Maximum·Age</ocil:title>101 ······<ocil:title>Disable·/dev/kmem·virtual·device·support</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-accounts_maximum_age_login_defs_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_devkmem_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> 
107 ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_ocil:questionnaire:1">
 107 ······<ocil:title>Configure·Accepting·Router·Advertisements·on·All·IPv6·Interfaces</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1">
113 ······<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>113 ······<ocil:title>Enable·Encrypted·X11·Forwarding</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-service_sshd_disabled_ocil:questionnaire:1"> 
119 ······<ocil:title>Disable·SSH·Server·If·Possible</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">
 119 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-service_sshd_disabled_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-partition_for_home_ocil:questionnaire:1">
Max diff block lines reached; 904133/916770 bytes (98.62%) of diff not shown.
557 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ds.xml
557 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS:ga:server">28 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS:ga:server">
29 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP1:ga:server">32 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP1:ga:server">
33 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP1</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP1</cpe-dict:title>
Offset 35, 15 lines modifiedOffset 35, 15 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP2:ga:server">36 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP2:ga:server">
37 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP2</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP2</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-xccdf.xml"·timestamp="2025-02-28T20:08:00">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-xccdf.xml"·timestamp="2025-03-01T22:08:00">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEULER2203"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEULER2203"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openEuler·2203</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openEuler·2203</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·openEuler·2203.·It·is·a·rendering·of48 configuration·settings·for·openEuler·2203.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 39461, 15 lines modifiedOffset 39461, 15 lines modified
39461 ··············<xccdf-1.2:check-content-ref·href="ssg-openeuler2203-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"/>39461 ··············<xccdf-1.2:check-content-ref·href="ssg-openeuler2203-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"/>
39462 ············</xccdf-1.2:check>39462 ············</xccdf-1.2:check>
39463 ··········</xccdf-1.2:Rule>39463 ··········</xccdf-1.2:Rule>
39464 ········</xccdf-1.2:Group>39464 ········</xccdf-1.2:Group>
39465 ······</xccdf-1.2:Group>39465 ······</xccdf-1.2:Group>
39466 ····</xccdf-1.2:Benchmark>39466 ····</xccdf-1.2:Benchmark>
39467 ··</ds:component>39467 ··</ds:component>
39468 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"·timestamp="2025-02-28T20:08:00">39468 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"·timestamp="2025-03-01T22:08:00">
39469 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">39469 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
39470 ······<oval-def:generator>39470 ······<oval-def:generator>
39471 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>39471 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
39472 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>39472 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
39473 ········<oval:schema_version>5.11</oval:schema_version>39473 ········<oval:schema_version>5.11</oval:schema_version>
39474 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>39474 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
39475 ······</oval-def:generator>39475 ······</oval-def:generator>
Offset 52232, 3174 lines modifiedOffset 52232, 3174 lines modified
52232 ············</oval-def:arithmetic>52232 ············</oval-def:arithmetic>
52233 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>52233 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
52234 ··········</oval-def:arithmetic>52234 ··········</oval-def:arithmetic>
52235 ········</oval-def:local_variable>52235 ········</oval-def:local_variable>
52236 ······</oval-def:variables>52236 ······</oval-def:variables>
52237 ····</oval-def:oval_definitions>52237 ····</oval-def:oval_definitions>
52238 ··</ds:component>52238 ··</ds:component>
52239 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"·timestamp="2025-02-28T20:08:00">52239 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"·timestamp="2025-03-01T22:08:00">
52240 ····<ocil:ocil>52240 ····<ocil:ocil>
52241 ······<ocil:generator>52241 ······<ocil:generator>
52242 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>52242 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
52243 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>52243 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
52244 ········<ocil:schema_version>2.0</ocil:schema_version>52244 ········<ocil:schema_version>2.0</ocil:schema_version>
52245 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>52245 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
52246 ······</ocil:generator>52246 ······</ocil:generator>
52247 ······<ocil:questionnaires>52247 ······<ocil:questionnaires>
52248 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1">52248 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">
52249 ··········<ocil:title>Verify·Permissions·on·/etc/at.allow·file</ocil:title>52249 ··········<ocil:title>Verify·Owner·on·cron.monthly</ocil:title>
52250 ··········<ocil:actions>52250 ··········<ocil:actions>
52251 ············<ocil:test_action_ref>ocil:ssg-file_permissions_at_allow_action:testaction:1</ocil:test_action_ref>52251 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>
52252 ··········</ocil:actions>52252 ··········</ocil:actions>
52253 ········</ocil:questionnaire>52253 ········</ocil:questionnaire>
52254 ········<ocil:questionnaire·id="ocil:ssg-service_avahi-daemon_disabled_ocil:questionnaire:1">52254 ········<ocil:questionnaire·id="ocil:ssg-service_nftables_enabled_ocil:questionnaire:1">
52255 ··········<ocil:title>Disable·Avahi·Server·Software</ocil:title>52255 ··········<ocil:title>Verify·nftables·Service·is·Enabled</ocil:title>
52256 ··········<ocil:actions>52256 ··········<ocil:actions>
52257 ············<ocil:test_action_ref>ocil:ssg-service_avahi-daemon_disabled_action:testaction:1</ocil:test_action_ref>52257 ············<ocil:test_action_ref>ocil:ssg-service_nftables_enabled_action:testaction:1</ocil:test_action_ref>
52258 ··········</ocil:actions>52258 ··········</ocil:actions>
52259 ········</ocil:questionnaire>52259 ········</ocil:questionnaire>
52260 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">52260 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_issue_ocil:questionnaire:1">
52261 ··········<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title>52261 ··········<ocil:title>Verify·ownership·of·System·Login·Banner</ocil:title>
52262 ··········<ocil:actions>52262 ··········<ocil:actions>
52263 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>52263 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_issue_action:testaction:1</ocil:test_action_ref>
52264 ··········</ocil:actions>52264 ··········</ocil:actions>
52265 ········</ocil:questionnaire>52265 ········</ocil:questionnaire>
52266 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_maxstartups_ocil:questionnaire:1">52266 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_ocil:questionnaire:1">
52267 ··········<ocil:title>Ensure·SSH·MaxStartups·is·configured</ocil:title>52267 ··········<ocil:title>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</ocil:title>
52268 ··········<ocil:actions>52268 ··········<ocil:actions>
52269 ············<ocil:test_action_ref>ocil:ssg-sshd_set_maxstartups_action:testaction:1</ocil:test_action_ref>52269 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_tcp_syncookies_action:testaction:1</ocil:test_action_ref>
52270 ··········</ocil:actions>52270 ··········</ocil:actions>
52271 ········</ocil:questionnaire>52271 ········</ocil:questionnaire>
52272 ········<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1">52272 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
52273 ··········<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>52273 ··········<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
52274 ··········<ocil:actions>52274 ··········<ocil:actions>
52275 ············<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>52275 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
52276 ··········</ocil:actions>52276 ··········</ocil:actions>
52277 ········</ocil:questionnaire>52277 ········</ocil:questionnaire>
52278 ········<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_macs_ocil:questionnaire:1">52278 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1">
52279 ··········<ocil:title>Use·Only·Strong·MACs</ocil:title>52279 ··········<ocil:title>Enable·PAM</ocil:title>
52280 ··········<ocil:actions>52280 ··········<ocil:actions>
52281 ············<ocil:test_action_ref>ocil:ssg-sshd_use_strong_macs_action:testaction:1</ocil:test_action_ref>52281 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_pam_action:testaction:1</ocil:test_action_ref>
52282 ··········</ocil:actions>52282 ··········</ocil:actions>
52283 ········</ocil:questionnaire>52283 ········</ocil:questionnaire>
52284 ········<ocil:questionnaire·id="ocil:ssg-no_forward_files_ocil:questionnaire:1">52284 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1">
52285 ··········<ocil:title>Verify·No·.forward·Files·Exist</ocil:title>52285 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Different·Categories</ocil:title>
52286 ··········<ocil:actions>52286 ··········<ocil:actions>
52287 ············<ocil:test_action_ref>ocil:ssg-no_forward_files_action:testaction:1</ocil:test_action_ref>52287 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minclass_action:testaction:1</ocil:test_action_ref>
52288 ··········</ocil:actions>52288 ··········</ocil:actions>
52289 ········</ocil:questionnaire>52289 ········</ocil:questionnaire>
52290 ········<ocil:questionnaire·id="ocil:ssg-selinux_policytype_ocil:questionnaire:1"> 
52291 ··········<ocil:title>Configure·SELinux·Policy</ocil:title>52290 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fsetxattr_ocil:questionnaire:1">
 52291 ··········<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fsetxattr</ocil:title>
52292 ··········<ocil:actions>52292 ··········<ocil:actions>
52293 ············<ocil:test_action_ref>ocil:ssg-selinux_policytype_action:testaction:1</ocil:test_action_ref>52293 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fsetxattr_action:testaction:1</ocil:test_action_ref>
52294 ··········</ocil:actions>52294 ··········</ocil:actions>
52295 ········</ocil:questionnaire>52295 ········</ocil:questionnaire>
52296 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_motd_ocil:questionnaire:1">52296 ········<ocil:questionnaire·id="ocil:ssg-nftables_ensure_default_deny_policy_ocil:questionnaire:1">
52297 ··········<ocil:title>Verify·permissions·on·Message·of·the·Day·Banner</ocil:title>52297 ··········<ocil:title>Ensure·nftables·Default·Deny·Firewall·Policy</ocil:title>
52298 ··········<ocil:actions>52298 ··········<ocil:actions>
52299 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_motd_action:testaction:1</ocil:test_action_ref>52299 ············<ocil:test_action_ref>ocil:ssg-nftables_ensure_default_deny_policy_action:testaction:1</ocil:test_action_ref>
52300 ··········</ocil:actions>52300 ··········</ocil:actions>
52301 ········</ocil:questionnaire>52301 ········</ocil:questionnaire>
52302 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_ocil:questionnaire:1">52302 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_ocil:questionnaire:1">
52303 ··········<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv6·Interfaces</ocil:title>52303 ··········<ocil:title>Enable·seccomp·to·safely·compute·untrusted·bytecode</ocil:title>
52304 ··········<ocil:actions>52304 ··········<ocil:actions>
52305 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>52305 ············<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_action:testaction:1</ocil:test_action_ref>
 52306 ··········</ocil:actions>
 52307 ········</ocil:questionnaire>
 52308 ········<ocil:questionnaire·id="ocil:ssg-package_httpd_removed_ocil:questionnaire:1">
 52309 ··········<ocil:title>Uninstall·httpd·Package</ocil:title>
Max diff block lines reached; 558329/570516 bytes (97.86%) of diff not shown.
529 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ocil.xml
529 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ocil.xml
Ordering differences only
    
Offset 3, 3165 lines modifiedOffset 3, 3165 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">
11 ······<ocil:title>Verify·Permissions·on·/etc/at.allow·file</ocil:title>11 ······<ocil:title>Verify·Owner·on·cron.monthly</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_at_allow_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-service_avahi-daemon_disabled_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-service_nftables_enabled_ocil:questionnaire:1">
17 ······<ocil:title>Disable·Avahi·Server·Software</ocil:title>17 ······<ocil:title>Verify·nftables·Service·is·Enabled</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-service_avahi-daemon_disabled_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-service_nftables_enabled_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_issue_ocil:questionnaire:1">
23 ······<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title>23 ······<ocil:title>Verify·ownership·of·System·Login·Banner</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_issue_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_maxstartups_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·SSH·MaxStartups·is·configured</ocil:title>29 ······<ocil:title>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sshd_set_maxstartups_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_tcp_syncookies_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1"> 
35 ······<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
 35 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_macs_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1">
41 ······<ocil:title>Use·Only·Strong·MACs</ocil:title>41 ······<ocil:title>Enable·PAM</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sshd_use_strong_macs_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_pam_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-no_forward_files_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1">
47 ······<ocil:title>Verify·No·.forward·Files·Exist</ocil:title>47 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Different·Categories</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-no_forward_files_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minclass_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-selinux_policytype_ocil:questionnaire:1"> 
53 ······<ocil:title>Configure·SELinux·Policy</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fsetxattr_ocil:questionnaire:1">
 53 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fsetxattr</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-selinux_policytype_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fsetxattr_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_motd_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-nftables_ensure_default_deny_policy_ocil:questionnaire:1">
59 ······<ocil:title>Verify·permissions·on·Message·of·the·Day·Banner</ocil:title>59 ······<ocil:title>Ensure·nftables·Default·Deny·Firewall·Policy</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_motd_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-nftables_ensure_default_deny_policy_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_ocil:questionnaire:1">
65 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv6·Interfaces</ocil:title>65 ······<ocil:title>Enable·seccomp·to·safely·compute·untrusted·bytecode</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_action:testaction:1</ocil:test_action_ref>
 68 ······</ocil:actions>
 69 ····</ocil:questionnaire>
 70 ····<ocil:questionnaire·id="ocil:ssg-package_httpd_removed_ocil:questionnaire:1">
 71 ······<ocil:title>Uninstall·httpd·Package</ocil:title>
 72 ······<ocil:actions>
 73 ········<ocil:test_action_ref>ocil:ssg-package_httpd_removed_action:testaction:1</ocil:test_action_ref>
 74 ······</ocil:actions>
 75 ····</ocil:questionnaire>
 76 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_macs_ocil:questionnaire:1">
 77 ······<ocil:title>Use·Only·Strong·MACs</ocil:title>
 78 ······<ocil:actions>
 79 ········<ocil:test_action_ref>ocil:ssg-sshd_use_strong_macs_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>80 ······</ocil:actions>
69 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_ocil:questionnaire:1">
71 ······<ocil:title>Disable·Kernel·Parameter·for·IPv6·Forwarding</ocil:title>83 ······<ocil:title>Disable·Kernel·Parameter·for·IPv6·Forwarding</ocil:title>
72 ······<ocil:actions>84 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>86 ······</ocil:actions>
75 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_motd_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1">
77 ······<ocil:title>Verify·ownership·of·Message·of·the·Day·Banner</ocil:title>89 ······<ocil:title>Set·SSH·MaxSessions·limit</ocil:title>
78 ······<ocil:actions>90 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_motd_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_sessions_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>92 ······</ocil:actions>
81 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-service_rsyslog_enabled_ocil:questionnaire:1"> 
83 ······<ocil:title>Enable·rsyslog·Service</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fchmodat_ocil:questionnaire:1">
 95 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fchmodat</ocil:title>
84 ······<ocil:actions>96 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-service_rsyslog_enabled_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fchmodat_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>98 ······</ocil:actions>
87 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-package_tftp-server_removed_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-package_aide_installed_ocil:questionnaire:1">
89 ······<ocil:title>Uninstall·tftp-server·Package</ocil:title>101 ······<ocil:title>Install·AIDE</ocil:title>
90 ······<ocil:actions>102 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-package_tftp-server_removed_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>104 ······</ocil:actions>
93 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1"> 
95 ······<ocil:title>Set·Lockout·Time·for·Failed·Password·Attempts</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_lsetxattr_ocil:questionnaire:1">
 107 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·lsetxattr</ocil:title>
96 ······<ocil:actions>108 ······<ocil:actions>
 109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>
 110 ······</ocil:actions>
 111 ····</ocil:questionnaire>
 112 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">
 113 ······<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>
 114 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_unlock_time_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>
 116 ······</ocil:actions>
 117 ····</ocil:questionnaire>
 118 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
 119 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
 120 ······<ocil:actions>
 121 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>122 ······</ocil:actions>
99 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1">
101 ······<ocil:title>Verify·Permissions·on·gshadow·File</ocil:title>125 ······<ocil:title>Verify·Permissions·on·gshadow·File</ocil:title>
Max diff block lines reached; 530432/541286 bytes (97.99%) of diff not shown.
676 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds.xml
676 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:15.0">28 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:15.0">
29 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·15.0</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·15.0</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap15:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap15:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.1">32 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.1">
33 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.1</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.1</cpe-dict:title>
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.3">40 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.3">
41 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.3</cpe-dict:title>41 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.3</cpe-dict:title>
42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap42:def:1</cpe-dict:check>42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap42:def:1</cpe-dict:check>
43 ······</cpe-dict:cpe-item>43 ······</cpe-dict:cpe-item>
44 ····</cpe-dict:cpe-list>44 ····</cpe-dict:cpe-list>
45 ··</ds:component>45 ··</ds:component>
46 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-xccdf.xml"·timestamp="2025-02-28T20:08:00">46 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-xccdf.xml"·timestamp="2025-03-01T22:08:00">
47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENSUSE"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENSUSE"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openSUSE</xccdf-1.2:title>49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openSUSE</xccdf-1.2:title>
50 ······<xccdf-1.2:description>50 ······<xccdf-1.2:description>
51 ········This·guide·presents·a·catalog·of·security-relevant51 ········This·guide·presents·a·catalog·of·security-relevant
52 configuration·settings·for·openSUSE.·It·is·a·rendering·of52 configuration·settings·for·openSUSE.·It·is·a·rendering·of
53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 41119, 15 lines modifiedOffset 41119, 15 lines modified
41119 ··············<xccdf-1.2:check-content-ref·href="ssg-opensuse-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>41119 ··············<xccdf-1.2:check-content-ref·href="ssg-opensuse-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
41120 ············</xccdf-1.2:check>41120 ············</xccdf-1.2:check>
41121 ··········</xccdf-1.2:Rule>41121 ··········</xccdf-1.2:Rule>
41122 ········</xccdf-1.2:Group>41122 ········</xccdf-1.2:Group>
41123 ······</xccdf-1.2:Group>41123 ······</xccdf-1.2:Group>
41124 ····</xccdf-1.2:Benchmark>41124 ····</xccdf-1.2:Benchmark>
41125 ··</ds:component>41125 ··</ds:component>
41126 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-oval.xml"·timestamp="2025-02-28T20:08:00">41126 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-oval.xml"·timestamp="2025-03-01T22:08:00">
41127 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">41127 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
41128 ······<oval-def:generator>41128 ······<oval-def:generator>
41129 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>41129 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
41130 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>41130 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
41131 ········<oval:schema_version>5.11</oval:schema_version>41131 ········<oval:schema_version>5.11</oval:schema_version>
41132 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>41132 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
41133 ······</oval-def:generator>41133 ······</oval-def:generator>
Offset 56631, 4186 lines modifiedOffset 56631, 4186 lines modified
56631 ············</oval-def:arithmetic>56631 ············</oval-def:arithmetic>
56632 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>56632 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
56633 ··········</oval-def:arithmetic>56633 ··········</oval-def:arithmetic>
56634 ········</oval-def:local_variable>56634 ········</oval-def:local_variable>
56635 ······</oval-def:variables>56635 ······</oval-def:variables>
56636 ····</oval-def:oval_definitions>56636 ····</oval-def:oval_definitions>
56637 ··</ds:component>56637 ··</ds:component>
56638 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-ocil.xml"·timestamp="2025-02-28T20:08:00">56638 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-ocil.xml"·timestamp="2025-03-01T22:08:00">
56639 ····<ocil:ocil>56639 ····<ocil:ocil>
56640 ······<ocil:generator>56640 ······<ocil:generator>
56641 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>56641 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
56642 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>56642 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
56643 ········<ocil:schema_version>2.0</ocil:schema_version>56643 ········<ocil:schema_version>2.0</ocil:schema_version>
56644 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>56644 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
56645 ······</ocil:generator>56645 ······</ocil:generator>
56646 ······<ocil:questionnaires>56646 ······<ocil:questionnaires>
56647 ········<ocil:questionnaire·id="ocil:ssg-service_chronyd_enabled_ocil:questionnaire:1">56647 ········<ocil:questionnaire·id="ocil:ssg-dir_ownership_library_dirs_ocil:questionnaire:1">
 56648 ··········<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Ownership</ocil:title>
56648 ··········<ocil:title>The·Chronyd·service·is·enabled</ocil:title> 
56649 ··········<ocil:actions> 
56650 ············<ocil:test_action_ref>ocil:ssg-service_chronyd_enabled_action:testaction:1</ocil:test_action_ref> 
56651 ··········</ocil:actions> 
56652 ········</ocil:questionnaire> 
56653 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_systemmap_ocil:questionnaire:1"> 
56654 ··········<ocil:title>Verify·Permissions·on·System.map·Files</ocil:title> 
56655 ··········<ocil:actions>56649 ··········<ocil:actions>
56656 ············<ocil:test_action_ref>ocil:ssg-file_permissions_systemmap_action:testaction:1</ocil:test_action_ref>56650 ············<ocil:test_action_ref>ocil:ssg-dir_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>
56657 ··········</ocil:actions>56651 ··········</ocil:actions>
56658 ········</ocil:questionnaire>56652 ········</ocil:questionnaire>
56659 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_security_writable_hooks_ocil:questionnaire:1">56653 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_legacy_ptys_ocil:questionnaire:1">
56660 ··········<ocil:title>Disable·mutable·hooks</ocil:title>56654 ··········<ocil:title>Disable·legacy·(BSD)·PTY·support</ocil:title>
56661 ··········<ocil:actions>56655 ··········<ocil:actions>
56662 ············<ocil:test_action_ref>ocil:ssg-kernel_config_security_writable_hooks_action:testaction:1</ocil:test_action_ref>56656 ············<ocil:test_action_ref>ocil:ssg-kernel_config_legacy_ptys_action:testaction:1</ocil:test_action_ref>
56663 ··········</ocil:actions>56657 ··········</ocil:actions>
56664 ········</ocil:questionnaire>56658 ········</ocil:questionnaire>
56665 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1"> 
56666 ··········<ocil:title>Disable·IPv6·Addressing·on·All·IPv6·Interfaces</ocil:title>56659 ········<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nodev_ocil:questionnaire:1">
 56660 ··········<ocil:title>Add·nodev·Option·to·/dev/shm</ocil:title>
56667 ··········<ocil:actions>56661 ··········<ocil:actions>
56668 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_action:testaction:1</ocil:test_action_ref>56662 ············<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nodev_action:testaction:1</ocil:test_action_ref>
56669 ··········</ocil:actions>56663 ··········</ocil:actions>
56670 ········</ocil:questionnaire>56664 ········</ocil:questionnaire>
56671 ········<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_audit_ocil:questionnaire:1"> 
56672 ··········<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>56665 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1">
 56666 ··········<ocil:title>Specify·module·signing·key·to·use</ocil:title>
56673 ··········<ocil:actions>56667 ··········<ocil:actions>
56674 ············<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>56668 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>
56675 ··········</ocil:actions>56669 ··········</ocil:actions>
56676 ········</ocil:questionnaire>56670 ········</ocil:questionnaire>
56677 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1">56671 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1">
56678 ··········<ocil:title>Disable·kernel·debugfs</ocil:title>56672 ··········<ocil:title>Disable·kernel·debugfs</ocil:title>
56679 ··········<ocil:actions>56673 ··········<ocil:actions>
56680 ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>56674 ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>
56681 ··········</ocil:actions>56675 ··········</ocil:actions>
56682 ········</ocil:questionnaire>56676 ········</ocil:questionnaire>
56683 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1">56677 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">
56684 ··········<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title>56678 ··········<ocil:title>Disable·TIPC·Support</ocil:title>
56685 ··········<ocil:actions>56679 ··········<ocil:actions>
56686 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref>56680 ············<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>
56687 ··········</ocil:actions>56681 ··········</ocil:actions>
56688 ········</ocil:questionnaire>56682 ········</ocil:questionnaire>
56689 ········<ocil:questionnaire·id="ocil:ssg-sudoers_no_command_negation_ocil:questionnaire:1"> 
56690 ··········<ocil:title>Don't·define·allowed·commands·in·sudoers·by·means·of·exclusion</ocil:title>56683 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_messages_ocil:questionnaire:1">
 56684 ··········<ocil:title>Verify·Permissions·on·/var/log/messages·File</ocil:title>
56691 ··········<ocil:actions>56685 ··········<ocil:actions>
56692 ············<ocil:test_action_ref>ocil:ssg-sudoers_no_command_negation_action:testaction:1</ocil:test_action_ref>56686 ············<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_messages_action:testaction:1</ocil:test_action_ref>
56693 ··········</ocil:actions>56687 ··········</ocil:actions>
56694 ········</ocil:questionnaire>56688 ········</ocil:questionnaire>
56695 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1">56689 ········<ocil:questionnaire·id="ocil:ssg-partition_for_home_ocil:questionnaire:1">
56696 ··········<ocil:title>Kernel·panic·timeout</ocil:title>56690 ··········<ocil:title>Ensure·/home·Located·On·Separate·Partition</ocil:title>
56697 ··········<ocil:actions>56691 ··········<ocil:actions>
56698 ············<ocil:test_action_ref>ocil:ssg-kernel_config_panic_timeout_action:testaction:1</ocil:test_action_ref>56692 ············<ocil:test_action_ref>ocil:ssg-partition_for_home_action:testaction:1</ocil:test_action_ref>
56699 ··········</ocil:actions>56693 ··········</ocil:actions>
56700 ········</ocil:questionnaire>56694 ········</ocil:questionnaire>
56701 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_gshadow_ocil:questionnaire:1">56695 ········<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1">
56702 ··········<ocil:title>Verify·Group·Who·Owns·Backup·gshadow·File</ocil:title>56696 ··········<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title>
56703 ··········<ocil:actions>56697 ··········<ocil:actions>
56704 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>56698 ············<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>
56705 ··········</ocil:actions>56699 ··········</ocil:actions>
Max diff block lines reached; 681711/692491 bytes (98.44%) of diff not shown.
643 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ocil.xml
643 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ocil.xml
Ordering differences only
    
Offset 3, 4177 lines modifiedOffset 3, 4177 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-service_chronyd_enabled_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_library_dirs_ocil:questionnaire:1">
 11 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Ownership</ocil:title>
11 ······<ocil:title>The·Chronyd·service·is·enabled</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-service_chronyd_enabled_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_systemmap_ocil:questionnaire:1"> 
17 ······<ocil:title>Verify·Permissions·on·System.map·Files</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_systemmap_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_writable_hooks_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_legacy_ptys_ocil:questionnaire:1">
23 ······<ocil:title>Disable·mutable·hooks</ocil:title>17 ······<ocil:title>Disable·legacy·(BSD)·PTY·support</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_writable_hooks_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_legacy_ptys_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1"> 
29 ······<ocil:title>Disable·IPv6·Addressing·on·All·IPv6·Interfaces</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nodev_ocil:questionnaire:1">
 23 ······<ocil:title>Add·nodev·Option·to·/dev/shm</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nodev_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_audit_ocil:questionnaire:1"> 
35 ······<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1">
 29 ······<ocil:title>Specify·module·signing·key·to·use</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1">
41 ······<ocil:title>Disable·kernel·debugfs</ocil:title>35 ······<ocil:title>Disable·kernel·debugfs</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">
47 ······<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title>41 ······<ocil:title>Disable·TIPC·Support</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_command_negation_ocil:questionnaire:1"> 
53 ······<ocil:title>Don't·define·allowed·commands·in·sudoers·by·means·of·exclusion</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_messages_ocil:questionnaire:1">
 47 ······<ocil:title>Verify·Permissions·on·/var/log/messages·File</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_command_negation_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_messages_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-partition_for_home_ocil:questionnaire:1">
59 ······<ocil:title>Kernel·panic·timeout</ocil:title>53 ······<ocil:title>Ensure·/home·Located·On·Separate·Partition</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_timeout_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-partition_for_home_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_gshadow_ocil:questionnaire:1"> 
65 ······<ocil:title>Verify·Group·Who·Owns·Backup·gshadow·File</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1">
 59 ······<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-service_ufw_enabled_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_clock_settime_ocil:questionnaire:1">
71 ······<ocil:title>Verify·ufw·Enabled</ocil:title>65 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·clock_settime</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-service_ufw_enabled_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_clock_settime_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_maxstartups_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
77 ······<ocil:title>Ensure·SSH·MaxStartups·is·configured</ocil:title>71 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sshd_set_maxstartups_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-service_ip6tables_enabled_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_command_negation_ocil:questionnaire:1">
83 ······<ocil:title>Verify·ip6tables·Enabled·if·Using·IPv6</ocil:title>77 ······<ocil:title>Don't·define·allowed·commands·in·sudoers·by·means·of·exclusion</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-service_ip6tables_enabled_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_command_negation_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1">
89 ······<ocil:title>Enable·different·security·models</ocil:title>83 ······<ocil:title>Configure·Polyinstantiation·of·/var/tmp·Directories</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_var_tmp_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1"> 
95 ······<ocil:title>Disable·TIPC·Support</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_ocil:questionnaire:1">
 89 ······<ocil:title>Disable·Accepting·Packets·Routed·Between·Local·Interfaces</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1"> 
101 ······<ocil:title>Disable·IA32·emulation</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1">
 95 ······<ocil:title>Ensure·No·World-Writable·Files·Exist</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_world_writable_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1"> 
107 ······<ocil:title>Set·Password·Warning·Age</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1">
 101 ······<ocil:title>IOMMU·configuration·directive</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-grub2_enable_iommu_force_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-package_ntp_installed_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1">
113 ······<ocil:title>Install·the·ntp·service</ocil:title>107 ······<ocil:title>Ensure·all·users·last·password·change·date·is·in·the·past</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-package_ntp_installed_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_shadow_ocil:questionnaire:1">
119 ······<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>113 ······<ocil:title>Verify·User·Who·Owns·Backup·shadow·File</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 646292/657790 bytes (98.25%) of diff not shown.
1.6 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds.xml
1.6 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux_coreos:4">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux_coreos:4">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·CoreOS·4</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·CoreOS·4</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml">oval:ssg-installed_OS_is_rhcos4:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml">oval:ssg-installed_OS_is_rhcos4:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHCOS-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHCOS-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Red·Hat·Enterprise·Linux·CoreOS·4.·It·is·a·rendering·of40 configuration·settings·for·Red·Hat·Enterprise·Linux·CoreOS·4.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 66389, 15 lines modifiedOffset 66389, 15 lines modified
66389 ··············<xccdf-1.2:check-content-ref·href="ssg-rhcos4-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>66389 ··············<xccdf-1.2:check-content-ref·href="ssg-rhcos4-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
66390 ············</xccdf-1.2:check>66390 ············</xccdf-1.2:check>
66391 ··········</xccdf-1.2:Rule>66391 ··········</xccdf-1.2:Rule>
66392 ········</xccdf-1.2:Group>66392 ········</xccdf-1.2:Group>
66393 ······</xccdf-1.2:Group>66393 ······</xccdf-1.2:Group>
66394 ····</xccdf-1.2:Benchmark>66394 ····</xccdf-1.2:Benchmark>
66395 ··</ds:component>66395 ··</ds:component>
66396 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-oval.xml"·timestamp="2025-02-28T20:08:00">66396 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-oval.xml"·timestamp="2025-03-01T22:08:00">
66397 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">66397 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
66398 ······<oval-def:generator>66398 ······<oval-def:generator>
66399 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>66399 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
66400 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>66400 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
66401 ········<oval:schema_version>5.11</oval:schema_version>66401 ········<oval:schema_version>5.11</oval:schema_version>
66402 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>66402 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
66403 ······</oval-def:generator>66403 ······</oval-def:generator>
Offset 104700, 12327 lines modifiedOffset 104700, 11751 lines modified
104700 ············</oval-def:arithmetic>104700 ············</oval-def:arithmetic>
104701 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>104701 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
104702 ··········</oval-def:arithmetic>104702 ··········</oval-def:arithmetic>
104703 ········</oval-def:local_variable>104703 ········</oval-def:local_variable>
104704 ······</oval-def:variables>104704 ······</oval-def:variables>
104705 ····</oval-def:oval_definitions>104705 ····</oval-def:oval_definitions>
104706 ··</ds:component>104706 ··</ds:component>
104707 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"·timestamp="2025-02-28T20:08:00">104707 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"·timestamp="2025-03-01T22:08:00">
104708 ····<ocil:ocil>104708 ····<ocil:ocil>
104709 ······<ocil:generator>104709 ······<ocil:generator>
104710 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>104710 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
104711 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>104711 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
104712 ········<ocil:schema_version>2.0</ocil:schema_version>104712 ········<ocil:schema_version>2.0</ocil:schema_version>
104713 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>104713 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
104714 ······</ocil:generator>104714 ······</ocil:generator>
104715 ······<ocil:questionnaires>104715 ······<ocil:questionnaires>
104716 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_chmod_ocil:questionnaire:1">104716 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_lsetxattr_ocil:questionnaire:1">
104717 ··········<ocil:title>Record·Unsuccessful·Permission·Changes·to·Files·-·chmod</ocil:title>104717 ··········<ocil:title>Record·Unsuccessful·Permission·Changes·to·Files·-·lsetxattr</ocil:title>
104718 ··········<ocil:actions> 
104719 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_chmod_action:testaction:1</ocil:test_action_ref> 
104720 ··········</ocil:actions> 
104721 ········</ocil:questionnaire> 
104722 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_ocil:questionnaire:1"> 
104723 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv6·Interfaces</ocil:title> 
104724 ··········<ocil:actions> 
104725 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref> 
104726 ··········</ocil:actions> 
104727 ········</ocil:questionnaire> 
104728 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_grub2_cfg_ocil:questionnaire:1"> 
104729 ··········<ocil:title>Verify·/boot/grub2/grub.cfg·Permissions</ocil:title> 
104730 ··········<ocil:actions> 
104731 ············<ocil:test_action_ref>ocil:ssg-file_permissions_grub2_cfg_action:testaction:1</ocil:test_action_ref> 
104732 ··········</ocil:actions> 
104733 ········</ocil:questionnaire> 
104734 ········<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nosuid_ocil:questionnaire:1"> 
104735 ··········<ocil:title>Add·nosuid·Option·to·/tmp</ocil:title> 
104736 ··········<ocil:actions>104718 ··········<ocil:actions>
104737 ············<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nosuid_action:testaction:1</ocil:test_action_ref>104719 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>
104738 ··········</ocil:actions>104720 ··········</ocil:actions>
104739 ········</ocil:questionnaire>104721 ········</ocil:questionnaire>
104740 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_ocil:questionnaire:1"> 
104741 ··········<ocil:title>Record·Unsuccessful·Delete·Attempts·to·Files·-·unlink</ocil:title>104722 ········<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">
 104723 ··········<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>
104742 ··········<ocil:actions>104724 ··········<ocil:actions>
104743 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_action:testaction:1</ocil:test_action_ref>104725 ············<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>
104744 ··········</ocil:actions>104726 ··········</ocil:actions>
104745 ········</ocil:questionnaire>104727 ········</ocil:questionnaire>
104746 ········<ocil:questionnaire·id="ocil:ssg-package_firewalld_installed_ocil:questionnaire:1">104728 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_ocil:questionnaire:1">
104747 ··········<ocil:title>Install·firewalld·Package</ocil:title>104729 ··········<ocil:title>Verify·User·Who·Owns·/var/log·Directory</ocil:title>
104748 ··········<ocil:actions>104730 ··········<ocil:actions>
104749 ············<ocil:test_action_ref>ocil:ssg-package_firewalld_installed_action:testaction:1</ocil:test_action_ref>104731 ············<ocil:test_action_ref>ocil:ssg-file_owner_var_log_action:testaction:1</ocil:test_action_ref>
104750 ··········</ocil:actions>104732 ··········</ocil:actions>
104751 ········</ocil:questionnaire>104733 ········</ocil:questionnaire>
104752 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_usernetctl_ocil:questionnaire:1"> 
104753 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·usernetctl</ocil:title>104734 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat_ocil:questionnaire:1">
 104735 ··········<ocil:title>Record·Unsuccessful·Creation·Attempts·to·Files·-·open_by_handle_at·O_CREAT</ocil:title>
104754 ··········<ocil:actions>104736 ··········<ocil:actions>
104755 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_usernetctl_action:testaction:1</ocil:test_action_ref>104737 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat_action:testaction:1</ocil:test_action_ref>
104756 ··········</ocil:actions>104738 ··········</ocil:actions>
104757 ········</ocil:questionnaire>104739 ········</ocil:questionnaire>
104758 ········<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1">104740 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1">
104759 ··········<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title>104741 ··········<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·by·Default</ocil:title>
104760 ··········<ocil:actions>104742 ··········<ocil:actions>
104761 ············<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref>104743 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_action:testaction:1</ocil:test_action_ref>
104762 ··········</ocil:actions>104744 ··········</ocil:actions>
104763 ········</ocil:questionnaire>104745 ········</ocil:questionnaire>
104764 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_systemmap_ocil:questionnaire:1">104746 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_flush_ocil:questionnaire:1">
104765 ··········<ocil:title>Verify·Permissions·on·System.map·Files</ocil:title>104747 ··········<ocil:title>Configure·auditd·flush·priority</ocil:title>
104766 ··········<ocil:actions>104748 ··········<ocil:actions>
104767 ············<ocil:test_action_ref>ocil:ssg-file_permissions_systemmap_action:testaction:1</ocil:test_action_ref>104749 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_flush_action:testaction:1</ocil:test_action_ref>
104768 ··········</ocil:actions>104750 ··········</ocil:actions>
104769 ········</ocil:questionnaire>104751 ········</ocil:questionnaire>
104770 ········<ocil:questionnaire·id="ocil:ssg-harden_openssl_crypto_policy_ocil:questionnaire:1"> 
104771 ··········<ocil:title>Harden·OpenSSL·Crypto·Policy</ocil:title>104752 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">
 104753 ··········<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>
104772 ··········<ocil:actions>104754 ··········<ocil:actions>
104773 ············<ocil:test_action_ref>ocil:ssg-harden_openssl_crypto_policy_action:testaction:1</ocil:test_action_ref>104755 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>
104774 ··········</ocil:actions>104756 ··········</ocil:actions>
104775 ········</ocil:questionnaire>104757 ········</ocil:questionnaire>
104776 ········<ocil:questionnaire·id="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1">104758 ········<ocil:questionnaire·id="ocil:ssg-directory_permissions_etc_selinux_ocil:questionnaire:1">
104777 ··········<ocil:title>Verify·Root·Has·A·Primary·GID·0</ocil:title>104759 ··········<ocil:title>Verify·Permissions·On·/etc/selinux·Directory</ocil:title>
104778 ··········<ocil:actions>104760 ··········<ocil:actions>
104779 ············<ocil:test_action_ref>ocil:ssg-accounts_root_gid_zero_action:testaction:1</ocil:test_action_ref>104761 ············<ocil:test_action_ref>ocil:ssg-directory_permissions_etc_selinux_action:testaction:1</ocil:test_action_ref>
104780 ··········</ocil:actions>104762 ··········</ocil:actions>
104781 ········</ocil:questionnaire>104763 ········</ocil:questionnaire>
104782 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">104764 ········<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1">
104783 ··········<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>104765 ··········<ocil:title>IOMMU·configuration·directive</ocil:title>
Max diff block lines reached; 1668246/1679735 bytes (99.32%) of diff not shown.
1.54 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ocil.xml
1.54 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ocil.xml
Ordering differences only
    
Offset 3, 12318 lines modifiedOffset 3, 11742 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_chmod_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_lsetxattr_ocil:questionnaire:1">
11 ······<ocil:title>Record·Unsuccessful·Permission·Changes·to·Files·-·chmod</ocil:title>11 ······<ocil:title>Record·Unsuccessful·Permission·Changes·to·Files·-·lsetxattr</ocil:title>
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_chmod_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_ocil:questionnaire:1"> 
17 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv6·Interfaces</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_grub2_cfg_ocil:questionnaire:1"> 
23 ······<ocil:title>Verify·/boot/grub2/grub.cfg·Permissions</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_grub2_cfg_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nosuid_ocil:questionnaire:1"> 
29 ······<ocil:title>Add·nosuid·Option·to·/tmp</ocil:title> 
30 ······<ocil:actions>12 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nosuid_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>14 ······</ocil:actions>
33 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_ocil:questionnaire:1"> 
35 ······<ocil:title>Record·Unsuccessful·Delete·Attempts·to·Files·-·unlink</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">
 17 ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>
36 ······<ocil:actions>18 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>20 ······</ocil:actions>
39 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-package_firewalld_installed_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_ocil:questionnaire:1">
41 ······<ocil:title>Install·firewalld·Package</ocil:title>23 ······<ocil:title>Verify·User·Who·Owns·/var/log·Directory</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-package_firewalld_installed_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_usernetctl_ocil:questionnaire:1"> 
47 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·usernetctl</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat_ocil:questionnaire:1">
 29 ······<ocil:title>Record·Unsuccessful·Creation·Attempts·to·Files·-·open_by_handle_at·O_CREAT</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_usernetctl_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1"> 
53 ······<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1">
 35 ······<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·by·Default</ocil:title>
54 ······<ocil:actions>36 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>38 ······</ocil:actions>
57 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_systemmap_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_flush_ocil:questionnaire:1">
59 ······<ocil:title>Verify·Permissions·on·System.map·Files</ocil:title>41 ······<ocil:title>Configure·auditd·flush·priority</ocil:title>
60 ······<ocil:actions>42 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_systemmap_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_flush_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>44 ······</ocil:actions>
63 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-harden_openssl_crypto_policy_ocil:questionnaire:1"> 
65 ······<ocil:title>Harden·OpenSSL·Crypto·Policy</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>
66 ······<ocil:actions>48 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-harden_openssl_crypto_policy_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>50 ······</ocil:actions>
69 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_etc_selinux_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Root·Has·A·Primary·GID·0</ocil:title>53 ······<ocil:title>Verify·Permissions·On·/etc/selinux·Directory</ocil:title>
72 ······<ocil:actions>54 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-accounts_root_gid_zero_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_etc_selinux_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>56 ······</ocil:actions>
75 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1">
77 ······<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>59 ······<ocil:title>IOMMU·configuration·directive</ocil:title>
78 ······<ocil:actions>60 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-grub2_enable_iommu_force_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>62 ······</ocil:actions>
81 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nosuid_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1">
83 ······<ocil:title>Add·nosuid·Option·to·/home</ocil:title>65 ······<ocil:title>Do·Not·Allow·SSH·Environment·Options</ocil:title>
84 ······<ocil:actions>66 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nosuid_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>68 ······</ocil:actions>
87 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_fsetxattr_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">
89 ······<ocil:title>Record·Unsuccessful·Permission·Changes·to·Files·-·fsetxattr</ocil:title>71 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>
90 ······<ocil:actions>72 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_fsetxattr_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>74 ······</ocil:actions>
93 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-configure_tmux_lock_command_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_clock_settime_ocil:questionnaire:1">
95 ······<ocil:title>Configure·the·tmux·Lock·Command</ocil:title>77 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·clock_settime</ocil:title>
96 ······<ocil:actions>78 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-configure_tmux_lock_command_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_clock_settime_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>80 ······</ocil:actions>
99 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-package_net-snmp_removed_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_ip_forward_ocil:questionnaire:1">
101 ······<ocil:title>Uninstall·net-snmp·Package</ocil:title>83 ······<ocil:title>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</ocil:title>
102 ······<ocil:actions>84 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-package_net-snmp_removed_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_forward_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>86 ······</ocil:actions>
105 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_rds_disabled_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_ocil:questionnaire:1">
107 ······<ocil:title>Disable·RDS·Support</ocil:title>89 ······<ocil:title>Record·Events·that·Modify·User/Group·Information</ocil:title>
108 ······<ocil:actions>90 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-kernel_module_rds_disabled_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>92 ······</ocil:actions>
111 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_etc_passwd_openat_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_etc_passwd_openat_ocil:questionnaire:1">
113 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·via·openat·syscall·-·/etc/passwd</ocil:title>95 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·via·openat·syscall·-·/etc/passwd</ocil:title>
114 ······<ocil:actions>96 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_etc_passwd_openat_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_etc_passwd_openat_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>98 ······</ocil:actions>
117 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_mount_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·mount</ocil:title>101 ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>
120 ······<ocil:actions>102 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_mount_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>104 ······</ocil:actions>
123 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_iwlwifi_disabled_ocil:questionnaire:1"> 
125 ······<ocil:title>Disable·Kernel·iwlwifi·Module</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1">
Max diff block lines reached; 1597768/1609738 bytes (99.26%) of diff not shown.
2.16 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ds.xml
2.16 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of40 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 312, 25 lines modifiedOffset 312, 25 lines modified
312 ··········</cpe-lang:logical-test>312 ··········</cpe-lang:logical-test>
313 ········</cpe-lang:platform>313 ········</cpe-lang:platform>
314 ········<cpe-lang:platform·id="package_bash">314 ········<cpe-lang:platform·id="package_bash">
315 ··········<cpe-lang:logical-test·operator="AND"·negate="false">315 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
316 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>316 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
317 ··········</cpe-lang:logical-test>317 ··········</cpe-lang:logical-test>
318 ········</cpe-lang:platform>318 ········</cpe-lang:platform>
319 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
320 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
321 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
322 ··········</cpe-lang:logical-test> 
323 ········</cpe-lang:platform> 
324 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">319 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
325 ··········<cpe-lang:logical-test·operator="AND"·negate="false">320 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
326 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>321 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
327 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>322 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
328 ··········</cpe-lang:logical-test>323 ··········</cpe-lang:logical-test>
329 ········</cpe-lang:platform>324 ········</cpe-lang:platform>
 325 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 326 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 327 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 328 ··········</cpe-lang:logical-test>
 329 ········</cpe-lang:platform>
330 ········<cpe-lang:platform·id="not_s390x_arch">330 ········<cpe-lang:platform·id="not_s390x_arch">
331 ··········<cpe-lang:logical-test·operator="AND"·negate="false">331 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
332 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>332 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
333 ··········</cpe-lang:logical-test>333 ··········</cpe-lang:logical-test>
334 ········</cpe-lang:platform>334 ········</cpe-lang:platform>
335 ········<cpe-lang:platform·id="package_tmux">335 ········<cpe-lang:platform·id="package_tmux">
336 ··········<cpe-lang:logical-test·operator="AND"·negate="false">336 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 216676, 15 lines modifiedOffset 216676, 15 lines modified
216676 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/>216676 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/>
216677 ············</xccdf-1.2:check>216677 ············</xccdf-1.2:check>
216678 ··········</xccdf-1.2:Rule>216678 ··········</xccdf-1.2:Rule>
216679 ········</xccdf-1.2:Group>216679 ········</xccdf-1.2:Group>
216680 ······</xccdf-1.2:Group>216680 ······</xccdf-1.2:Group>
216681 ····</xccdf-1.2:Benchmark>216681 ····</xccdf-1.2:Benchmark>
216682 ··</ds:component>216682 ··</ds:component>
216683 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-02-28T20:08:00">216683 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-03-01T22:08:00">
216684 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">216684 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
216685 ······<oval-def:generator>216685 ······<oval-def:generator>
216686 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>216686 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
216687 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>216687 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
216688 ········<oval:schema_version>5.11</oval:schema_version>216688 ········<oval:schema_version>5.11</oval:schema_version>
216689 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>216689 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
216690 ······</oval-def:generator>216690 ······</oval-def:generator>
Offset 266291, 13145 lines modifiedOffset 266291, 13748 lines modified
266291 ············</oval-def:arithmetic>266291 ············</oval-def:arithmetic>
266292 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>266292 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
266293 ··········</oval-def:arithmetic>266293 ··········</oval-def:arithmetic>
266294 ········</oval-def:local_variable>266294 ········</oval-def:local_variable>
266295 ······</oval-def:variables>266295 ······</oval-def:variables>
266296 ····</oval-def:oval_definitions>266296 ····</oval-def:oval_definitions>
266297 ··</ds:component>266297 ··</ds:component>
266298 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-02-28T20:08:00">266298 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-03-01T22:08:00">
266299 ····<ocil:ocil>266299 ····<ocil:ocil>
266300 ······<ocil:generator>266300 ······<ocil:generator>
266301 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>266301 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
266302 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>266302 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
266303 ········<ocil:schema_version>2.0</ocil:schema_version>266303 ········<ocil:schema_version>2.0</ocil:schema_version>
266304 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>266304 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
266305 ······</ocil:generator>266305 ······</ocil:generator>
266306 ······<ocil:questionnaires>266306 ······<ocil:questionnaires>
266307 ········<ocil:questionnaire·id="ocil:ssg-audit_modify_failed_ppc64le_ocil:questionnaire:1">266307 ········<ocil:questionnaire·id="ocil:ssg-use_pam_wheel_for_su_ocil:questionnaire:1">
266308 ··········<ocil:title>Configure·auditing·of·unsuccessful·file·modifications·(ppc64le)</ocil:title>266308 ··········<ocil:title>Enforce·usage·of·pam_wheel·for·su·authentication</ocil:title>
266309 ··········<ocil:actions>266309 ··········<ocil:actions>
266310 ············<ocil:test_action_ref>ocil:ssg-audit_modify_failed_ppc64le_action:testaction:1</ocil:test_action_ref>266310 ············<ocil:test_action_ref>ocil:ssg-use_pam_wheel_for_su_action:testaction:1</ocil:test_action_ref>
266311 ··········</ocil:actions>266311 ··········</ocil:actions>
266312 ········</ocil:questionnaire>266312 ········</ocil:questionnaire>
266313 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_user_cfg_ocil:questionnaire:1">266313 ········<ocil:questionnaire·id="ocil:ssg-root_permissions_syslibrary_files_ocil:questionnaire:1">
266314 ··········<ocil:title>Verify·/boot/grub2/user.cfg·Permissions</ocil:title>266314 ··········<ocil:title>Verify·the·system-wide·library·files·in·directories
 266315 "/lib",·"/lib64",·"/usr/lib/"·and·"/usr/lib64"·are·group-owned·by·root.</ocil:title>
266315 ··········<ocil:actions>266316 ··········<ocil:actions>
266316 ············<ocil:test_action_ref>ocil:ssg-file_permissions_user_cfg_action:testaction:1</ocil:test_action_ref>266317 ············<ocil:test_action_ref>ocil:ssg-root_permissions_syslibrary_files_action:testaction:1</ocil:test_action_ref>
266317 ··········</ocil:actions>266318 ··········</ocil:actions>
266318 ········</ocil:questionnaire>266319 ········</ocil:questionnaire>
266319 ········<ocil:questionnaire·id="ocil:ssg-accounts_users_home_files_permissions_ocil:questionnaire:1"> 
266320 ··········<ocil:title>All·User·Files·and·Directories·In·The·Home·Directory·Must·Have·Mode·0750·Or·Less·Permissive</ocil:title>266320 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_pubkey_auth_ocil:questionnaire:1">
 266321 ··········<ocil:title>Enable·Public·Key·Authentication</ocil:title>
266321 ··········<ocil:actions>266322 ··········<ocil:actions>
266322 ············<ocil:test_action_ref>ocil:ssg-accounts_users_home_files_permissions_action:testaction:1</ocil:test_action_ref>266323 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
266323 ··········</ocil:actions>266324 ··········</ocil:actions>
266324 ········</ocil:questionnaire>266325 ········</ocil:questionnaire>
266325 ········<ocil:questionnaire·id="ocil:ssg-xwindows_runlevel_target_ocil:questionnaire:1">266326 ········<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
266326 ··········<ocil:title>Disable·Graphical·Environment·Startup·By·Setting·Default·Target</ocil:title>266327 ··········<ocil:title>Enable·systemd-journald·Service</ocil:title>
266327 ··········<ocil:actions>266328 ··········<ocil:actions>
266328 ············<ocil:test_action_ref>ocil:ssg-xwindows_runlevel_target_action:testaction:1</ocil:test_action_ref>266329 ············<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
266329 ··········</ocil:actions>266330 ··········</ocil:actions>
266330 ········</ocil:questionnaire>266331 ········</ocil:questionnaire>
266331 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sudoers_ocil:questionnaire:1">266332 ········<ocil:questionnaire·id="ocil:ssg-disable_ctrlaltdel_burstaction_ocil:questionnaire:1">
266332 ··········<ocil:title>Verify·Group·Who·Owns·/etc/sudoers·File</ocil:title>266333 ··········<ocil:title>Disable·Ctrl-Alt-Del·Burst·Action</ocil:title>
266333 ··········<ocil:actions>266334 ··········<ocil:actions>
266334 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sudoers_action:testaction:1</ocil:test_action_ref>266335 ············<ocil:test_action_ref>ocil:ssg-disable_ctrlaltdel_burstaction_action:testaction:1</ocil:test_action_ref>
266335 ··········</ocil:actions>266336 ··········</ocil:actions>
266336 ········</ocil:questionnaire>266337 ········</ocil:questionnaire>
266337 ········<ocil:questionnaire·id="ocil:ssg-audit_ospp_general_ppc64le_ocil:questionnaire:1">266338 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1">
266338 ··········<ocil:title>Perform·general·configuration·of·Audit·for·OSPP·(ppc64le)</ocil:title>266339 ··········<ocil:title>Disable·kernel·debugfs</ocil:title>
266339 ··········<ocil:actions>266340 ··········<ocil:actions>
266340 ············<ocil:test_action_ref>ocil:ssg-audit_ospp_general_ppc64le_action:testaction:1</ocil:test_action_ref>266341 ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>
266341 ··········</ocil:actions>266342 ··········</ocil:actions>
266342 ········</ocil:questionnaire>266343 ········</ocil:questionnaire>
266343 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_can_disabled_ocil:questionnaire:1">266344 ········<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_noexec_ocil:questionnaire:1">
266344 ··········<ocil:title>Disable·CAN·Support</ocil:title>266345 ··········<ocil:title>Add·noexec·Option·to·/dev/shm</ocil:title>
Max diff block lines reached; 2251967/2262988 bytes (99.51%) of diff not shown.
2.05 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ocil.xml
2.05 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ocil.xml
Ordering differences only
    
Offset 3, 13136 lines modifiedOffset 3, 13739 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_modify_failed_ppc64le_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-use_pam_wheel_for_su_ocil:questionnaire:1">
11 ······<ocil:title>Configure·auditing·of·unsuccessful·file·modifications·(ppc64le)</ocil:title>11 ······<ocil:title>Enforce·usage·of·pam_wheel·for·su·authentication</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-audit_modify_failed_ppc64le_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-use_pam_wheel_for_su_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_user_cfg_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-root_permissions_syslibrary_files_ocil:questionnaire:1">
17 ······<ocil:title>Verify·/boot/grub2/user.cfg·Permissions</ocil:title>17 ······<ocil:title>Verify·the·system-wide·library·files·in·directories
 18 "/lib",·"/lib64",·"/usr/lib/"·and·"/usr/lib64"·are·group-owned·by·root.</ocil:title>
18 ······<ocil:actions>19 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_user_cfg_action:testaction:1</ocil:test_action_ref>20 ········<ocil:test_action_ref>ocil:ssg-root_permissions_syslibrary_files_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>21 ······</ocil:actions>
21 ····</ocil:questionnaire>22 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-accounts_users_home_files_permissions_ocil:questionnaire:1"> 
23 ······<ocil:title>All·User·Files·and·Directories·In·The·Home·Directory·Must·Have·Mode·0750·Or·Less·Permissive</ocil:title>23 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_pubkey_auth_ocil:questionnaire:1">
 24 ······<ocil:title>Enable·Public·Key·Authentication</ocil:title>
24 ······<ocil:actions>25 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-accounts_users_home_files_permissions_action:testaction:1</ocil:test_action_ref>26 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>27 ······</ocil:actions>
27 ····</ocil:questionnaire>28 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-xwindows_runlevel_target_ocil:questionnaire:1">29 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
29 ······<ocil:title>Disable·Graphical·Environment·Startup·By·Setting·Default·Target</ocil:title>30 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
30 ······<ocil:actions>31 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-xwindows_runlevel_target_action:testaction:1</ocil:test_action_ref>32 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>33 ······</ocil:actions>
33 ····</ocil:questionnaire>34 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sudoers_ocil:questionnaire:1">35 ····<ocil:questionnaire·id="ocil:ssg-disable_ctrlaltdel_burstaction_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Group·Who·Owns·/etc/sudoers·File</ocil:title>36 ······<ocil:title>Disable·Ctrl-Alt-Del·Burst·Action</ocil:title>
36 ······<ocil:actions>37 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sudoers_action:testaction:1</ocil:test_action_ref>38 ········<ocil:test_action_ref>ocil:ssg-disable_ctrlaltdel_burstaction_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>39 ······</ocil:actions>
39 ····</ocil:questionnaire>40 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_ospp_general_ppc64le_ocil:questionnaire:1">41 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1">
41 ······<ocil:title>Perform·general·configuration·of·Audit·for·OSPP·(ppc64le)</ocil:title>42 ······<ocil:title>Disable·kernel·debugfs</ocil:title>
42 ······<ocil:actions>43 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_ospp_general_ppc64le_action:testaction:1</ocil:test_action_ref>44 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>45 ······</ocil:actions>
45 ····</ocil:questionnaire>46 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_can_disabled_ocil:questionnaire:1">47 ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_noexec_ocil:questionnaire:1">
47 ······<ocil:title>Disable·CAN·Support</ocil:title>48 ······<ocil:title>Add·noexec·Option·to·/dev/shm</ocil:title>
48 ······<ocil:actions>49 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-kernel_module_can_disabled_action:testaction:1</ocil:test_action_ref>50 ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_noexec_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>51 ······</ocil:actions>
51 ····</ocil:questionnaire>52 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-package_tftp_removed_ocil:questionnaire:1">53 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_macs_ocil:questionnaire:1">
53 ······<ocil:title>Remove·tftp·Daemon</ocil:title>54 ······<ocil:title>Use·Only·Strong·MACs</ocil:title>
54 ······<ocil:actions>55 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-package_tftp_removed_action:testaction:1</ocil:test_action_ref>56 ········<ocil:test_action_ref>ocil:ssg-sshd_use_strong_macs_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>57 ······</ocil:actions>
57 ····</ocil:questionnaire>58 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_yama_ptrace_scope_ocil:questionnaire:1">59 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sestatus_conf_ocil:questionnaire:1">
59 ······<ocil:title>Restrict·usage·of·ptrace·to·descendant·processes</ocil:title>60 ······<ocil:title>Verify·Group·Who·Owns·/etc/sestatus.conf·File</ocil:title>
60 ······<ocil:actions>61 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_yama_ptrace_scope_action:testaction:1</ocil:test_action_ref>62 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>63 ······</ocil:actions>
63 ····</ocil:questionnaire>64 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1">65 ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_noexec_ocil:questionnaire:1">
65 ······<ocil:title>Verify·Permissions·on·/etc/cron.allow·file</ocil:title>66 ······<ocil:title>Add·noexec·Option·to·/tmp</ocil:title>
66 ······<ocil:actions>67 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_allow_action:testaction:1</ocil:test_action_ref>68 ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_noexec_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>69 ······</ocil:actions>
69 ····</ocil:questionnaire>70 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-grub2_mds_argument_ocil:questionnaire:1">71 ····<ocil:questionnaire·id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1">
71 ······<ocil:title>Configure·Microarchitectural·Data·Sampling·mitigation</ocil:title>72 ······<ocil:title>Ensure·gnutls-utils·is·installed</ocil:title>
72 ······<ocil:actions>73 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-grub2_mds_argument_action:testaction:1</ocil:test_action_ref>74 ········<ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>75 ······</ocil:actions>
75 ····</ocil:questionnaire>76 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1">77 ····<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1">
77 ······<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>78 ······<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title>
78 ······<ocil:actions>79 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>80 ········<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>81 ······</ocil:actions>
81 ····</ocil:questionnaire>82 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_audit_ocil:questionnaire:1"> 
83 ······<ocil:title>System·Audit·Logs·Must·Have·Mode·0640·or·Less·Permissive</ocil:title>83 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_csh_cshrc_ocil:questionnaire:1">
 84 ······<ocil:title>Ensure·the·Default·C·Shell·Umask·is·Set·Correctly</ocil:title>
84 ······<ocil:actions>85 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref>86 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_csh_cshrc_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>87 ······</ocil:actions>
87 ····</ocil:questionnaire>88 ····</ocil:questionnaire>
 89 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1">
 90 ······<ocil:title>Ensure·SMAP·is·not·disabled·during·boot</ocil:title>
88 ····<ocil:questionnaire·id="ocil:ssg-root_permissions_syslibrary_files_ocil:questionnaire:1"> 
89 ······<ocil:title>Verify·the·system-wide·library·files·in·directories 
90 "/lib",·"/lib64",·"/usr/lib/"·and·"/usr/lib64"·are·group-owned·by·root.</ocil:title> 
91 ······<ocil:actions>91 ······<ocil:actions>
92 ········<ocil:test_action_ref>ocil:ssg-root_permissions_syslibrary_files_action:testaction:1</ocil:test_action_ref>92 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1</ocil:test_action_ref>
93 ······</ocil:actions>93 ······</ocil:actions>
94 ····</ocil:questionnaire>94 ····</ocil:questionnaire>
95 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1">95 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_modules_disabled_ocil:questionnaire:1">
96 ······<ocil:title>Disable·GSSAPI·Authentication</ocil:title>96 ······<ocil:title>Disable·loading·and·unloading·of·kernel·modules</ocil:title>
97 ······<ocil:actions>97 ······<ocil:actions>
98 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_gssapi_auth_action:testaction:1</ocil:test_action_ref>98 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_modules_disabled_action:testaction:1</ocil:test_action_ref>
99 ······</ocil:actions>99 ······</ocil:actions>
100 ····</ocil:questionnaire>100 ····</ocil:questionnaire>
101 ····<ocil:questionnaire·id="ocil:ssg-ssh_keys_passphrase_protected_ocil:questionnaire:1">101 ····<ocil:questionnaire·id="ocil:ssg-account_unique_id_ocil:questionnaire:1">
102 ······<ocil:title>Verify·the·SSH·Private·Key·Files·Have·a·Passcode</ocil:title>102 ······<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·User·IDs</ocil:title>
103 ······<ocil:actions>103 ······<ocil:actions>
104 ········<ocil:test_action_ref>ocil:ssg-ssh_keys_passphrase_protected_action:testaction:1</ocil:test_action_ref>104 ········<ocil:test_action_ref>ocil:ssg-account_unique_id_action:testaction:1</ocil:test_action_ref>
105 ······</ocil:actions>105 ······</ocil:actions>
106 ····</ocil:questionnaire>106 ····</ocil:questionnaire>
107 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_ipsec_secrets_ocil:questionnaire:1">107 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_filter_ocil:questionnaire:1">
108 ······<ocil:title>Verify·User·Who·Owns·/etc/ipsec.secrets·File</ocil:title>108 ······<ocil:title>Enable·use·of·Berkeley·Packet·Filter·with·seccomp</ocil:title>
109 ······<ocil:actions>109 ······<ocil:actions>
110 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_ipsec_secrets_action:testaction:1</ocil:test_action_ref>110 ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_filter_action:testaction:1</ocil:test_action_ref>
111 ······</ocil:actions>111 ······</ocil:actions>
112 ····</ocil:questionnaire>112 ····</ocil:questionnaire>
113 ····<ocil:questionnaire·id="ocil:ssg-usbguard_generate_policy_ocil:questionnaire:1">113 ····<ocil:questionnaire·id="ocil:ssg-no_password_auth_for_systemaccounts_ocil:questionnaire:1">
114 ······<ocil:title>Generate·USBGuard·Policy</ocil:title>114 ······<ocil:title>Ensure·that·System·Accounts·Are·Locked</ocil:title>
115 ······<ocil:actions>115 ······<ocil:actions>
116 ········<ocil:test_action_ref>ocil:ssg-usbguard_generate_policy_action:testaction:1</ocil:test_action_ref>116 ········<ocil:test_action_ref>ocil:ssg-no_password_auth_for_systemaccounts_action:testaction:1</ocil:test_action_ref>
117 ······</ocil:actions>117 ······</ocil:actions>
118 ····</ocil:questionnaire>118 ····</ocil:questionnaire>
119 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">119 ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_permissions_ocil:questionnaire:1">
120 ······<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>120 ······<ocil:title>Verify·and·Correct·File·Permissions·with·RPM</ocil:title>
121 ······<ocil:actions>121 ······<ocil:actions>
122 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>122 ········<ocil:test_action_ref>ocil:ssg-rpm_verify_permissions_action:testaction:1</ocil:test_action_ref>
123 ······</ocil:actions>123 ······</ocil:actions>
124 ····</ocil:questionnaire>124 ····</ocil:questionnaire>
Max diff block lines reached; 2141589/2154218 bytes (99.41%) of diff not shown.
2.3 KB
./usr/share/xml/scap/ssg/content/ssg-rhel10-xccdf.xml
2.2 KB
./usr/share/xml/scap/ssg/content/ssg-rhel10-xccdf.xml
Ordering differences only
    
Offset 279, 25 lines modifiedOffset 279, 25 lines modified
279 ······</cpe-lang:logical-test>279 ······</cpe-lang:logical-test>
280 ····</cpe-lang:platform>280 ····</cpe-lang:platform>
281 ····<cpe-lang:platform·id="package_bash">281 ····<cpe-lang:platform·id="package_bash">
282 ······<cpe-lang:logical-test·operator="AND"·negate="false">282 ······<cpe-lang:logical-test·operator="AND"·negate="false">
283 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>283 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
284 ······</cpe-lang:logical-test>284 ······</cpe-lang:logical-test>
285 ····</cpe-lang:platform>285 ····</cpe-lang:platform>
286 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
287 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
288 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
289 ······</cpe-lang:logical-test> 
290 ····</cpe-lang:platform> 
291 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">286 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
292 ······<cpe-lang:logical-test·operator="AND"·negate="false">287 ······<cpe-lang:logical-test·operator="AND"·negate="false">
293 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>288 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
294 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>289 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
295 ······</cpe-lang:logical-test>290 ······</cpe-lang:logical-test>
296 ····</cpe-lang:platform>291 ····</cpe-lang:platform>
 292 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 293 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 294 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 295 ······</cpe-lang:logical-test>
 296 ····</cpe-lang:platform>
297 ····<cpe-lang:platform·id="not_s390x_arch">297 ····<cpe-lang:platform·id="not_s390x_arch">
298 ······<cpe-lang:logical-test·operator="AND"·negate="false">298 ······<cpe-lang:logical-test·operator="AND"·negate="false">
299 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>299 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
300 ······</cpe-lang:logical-test>300 ······</cpe-lang:logical-test>
301 ····</cpe-lang:platform>301 ····</cpe-lang:platform>
302 ····<cpe-lang:platform·id="package_tmux">302 ····<cpe-lang:platform·id="package_tmux">
303 ······<cpe-lang:logical-test·operator="AND"·negate="false">303 ······<cpe-lang:logical-test·operator="AND"·negate="false">
3.42 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
3.42 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>
Offset 71, 15 lines modifiedOffset 71, 15 lines modified
71 ······</cpe-dict:cpe-item>71 ······</cpe-dict:cpe-item>
72 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.9">72 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.9">
73 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.9</cpe-dict:title>73 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.9</cpe-dict:title>
74 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8_9:def:1</cpe-dict:check>74 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8_9:def:1</cpe-dict:check>
75 ······</cpe-dict:cpe-item>75 ······</cpe-dict:cpe-item>
76 ····</cpe-dict:cpe-list>76 ····</cpe-dict:cpe-list>
77 ··</ds:component>77 ··</ds:component>
78 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-02-28T20:08:00">78 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
79 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">79 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
80 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>80 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
81 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>81 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>
82 ······<xccdf-1.2:description>82 ······<xccdf-1.2:description>
83 ········This·guide·presents·a·catalog·of·security-relevant83 ········This·guide·presents·a·catalog·of·security-relevant
84 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of84 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of
85 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)85 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 434, 25 lines modifiedOffset 434, 25 lines modified
434 ··········</cpe-lang:logical-test>434 ··········</cpe-lang:logical-test>
435 ········</cpe-lang:platform>435 ········</cpe-lang:platform>
436 ········<cpe-lang:platform·id="package_bash">436 ········<cpe-lang:platform·id="package_bash">
437 ··········<cpe-lang:logical-test·operator="AND"·negate="false">437 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
438 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>438 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
439 ··········</cpe-lang:logical-test>439 ··········</cpe-lang:logical-test>
440 ········</cpe-lang:platform>440 ········</cpe-lang:platform>
441 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
442 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
443 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
444 ··········</cpe-lang:logical-test> 
445 ········</cpe-lang:platform> 
446 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">441 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
447 ··········<cpe-lang:logical-test·operator="AND"·negate="false">442 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
448 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>443 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
449 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>444 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
450 ··········</cpe-lang:logical-test>445 ··········</cpe-lang:logical-test>
451 ········</cpe-lang:platform>446 ········</cpe-lang:platform>
 447 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 448 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 449 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 450 ··········</cpe-lang:logical-test>
 451 ········</cpe-lang:platform>
452 ········<cpe-lang:platform·id="not_s390x_arch">452 ········<cpe-lang:platform·id="not_s390x_arch">
453 ··········<cpe-lang:logical-test·operator="AND"·negate="false">453 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
454 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>454 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
455 ··········</cpe-lang:logical-test>455 ··········</cpe-lang:logical-test>
456 ········</cpe-lang:platform>456 ········</cpe-lang:platform>
457 ········<cpe-lang:platform·id="package_tmux">457 ········<cpe-lang:platform·id="package_tmux">
458 ··········<cpe-lang:logical-test·operator="AND"·negate="false">458 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 317526, 15 lines modifiedOffset 317526, 15 lines modified
317526 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>317526 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
317527 ············</xccdf-1.2:check>317527 ············</xccdf-1.2:check>
317528 ··········</xccdf-1.2:Rule>317528 ··········</xccdf-1.2:Rule>
317529 ········</xccdf-1.2:Group>317529 ········</xccdf-1.2:Group>
317530 ······</xccdf-1.2:Group>317530 ······</xccdf-1.2:Group>
317531 ····</xccdf-1.2:Benchmark>317531 ····</xccdf-1.2:Benchmark>
317532 ··</ds:component>317532 ··</ds:component>
317533 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-02-28T20:08:00">317533 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-03-01T22:08:00">
317534 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">317534 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
317535 ······<oval-def:generator>317535 ······<oval-def:generator>
317536 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>317536 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
317537 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>317537 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
317538 ········<oval:schema_version>5.11</oval:schema_version>317538 ········<oval:schema_version>5.11</oval:schema_version>
317539 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>317539 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
317540 ······</oval-def:generator>317540 ······</oval-def:generator>
Offset 385018, 12335 lines modifiedOffset 385018, 12335 lines modified
385018 ············</oval-def:arithmetic>385018 ············</oval-def:arithmetic>
385019 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>385019 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>
385020 ··········</oval-def:arithmetic>385020 ··········</oval-def:arithmetic>
385021 ········</oval-def:local_variable>385021 ········</oval-def:local_variable>
385022 ······</oval-def:variables>385022 ······</oval-def:variables>
385023 ····</oval-def:oval_definitions>385023 ····</oval-def:oval_definitions>
385024 ··</ds:component>385024 ··</ds:component>
385025 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-02-28T20:08:00">385025 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-03-01T22:08:00">
385026 ····<ocil:ocil>385026 ····<ocil:ocil>
385027 ······<ocil:generator>385027 ······<ocil:generator>
385028 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>385028 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
385029 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>385029 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
385030 ········<ocil:schema_version>2.0</ocil:schema_version>385030 ········<ocil:schema_version>2.0</ocil:schema_version>
385031 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>385031 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
385032 ······</ocil:generator>385032 ······</ocil:generator>
385033 ······<ocil:questionnaires>385033 ······<ocil:questionnaires>
385034 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">385034 ········<ocil:questionnaire·id="ocil:ssg-nfs_no_anonymous_ocil:questionnaire:1">
385035 ··········<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>385035 ··········<ocil:title>Specify·UID·and·GID·for·Anonymous·NFS·Connections</ocil:title>
385036 ··········<ocil:actions>385036 ··········<ocil:actions>
385037 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>385037 ············<ocil:test_action_ref>ocil:ssg-nfs_no_anonymous_action:testaction:1</ocil:test_action_ref>
385038 ··········</ocil:actions>385038 ··········</ocil:actions>
385039 ········</ocil:questionnaire>385039 ········</ocil:questionnaire>
385040 ········<ocil:questionnaire·id="ocil:ssg-package_tftp_removed_ocil:questionnaire:1">385040 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1">
385041 ··········<ocil:title>Remove·tftp·Daemon</ocil:title>385041 ··········<ocil:title>Verify·Permissions·on·/etc/at.allow·file</ocil:title>
385042 ··········<ocil:actions>385042 ··········<ocil:actions>
385043 ············<ocil:test_action_ref>ocil:ssg-package_tftp_removed_action:testaction:1</ocil:test_action_ref>385043 ············<ocil:test_action_ref>ocil:ssg-file_permissions_at_allow_action:testaction:1</ocil:test_action_ref>
385044 ··········</ocil:actions>385044 ··········</ocil:actions>
385045 ········</ocil:questionnaire>385045 ········</ocil:questionnaire>
385046 ········<ocil:questionnaire·id="ocil:ssg-ldap_client_start_tls_ocil:questionnaire:1">385046 ········<ocil:questionnaire·id="ocil:ssg-audit_ospp_general_ocil:questionnaire:1">
385047 ··········<ocil:title>Configure·LDAP·Client·to·Use·TLS·For·All·Transactions</ocil:title>385047 ··········<ocil:title>Perform·general·configuration·of·Audit·for·OSPP</ocil:title>
385048 ··········<ocil:actions>385048 ··········<ocil:actions>
385049 ············<ocil:test_action_ref>ocil:ssg-ldap_client_start_tls_action:testaction:1</ocil:test_action_ref>385049 ············<ocil:test_action_ref>ocil:ssg-audit_ospp_general_action:testaction:1</ocil:test_action_ref>
385050 ··········</ocil:actions>385050 ··········</ocil:actions>
385051 ········</ocil:questionnaire>385051 ········</ocil:questionnaire>
385052 ········<ocil:questionnaire·id="ocil:ssg-service_sshd_enabled_ocil:questionnaire:1">385052 ········<ocil:questionnaire·id="ocil:ssg-sebool_daemons_dump_core_ocil:questionnaire:1">
385053 ··········<ocil:title>Enable·the·OpenSSH·Service</ocil:title>385053 ··········<ocil:title>Disable·the·daemons_dump_core·SELinux·Boolean</ocil:title>
385054 ··········<ocil:actions>385054 ··········<ocil:actions>
385055 ············<ocil:test_action_ref>ocil:ssg-service_sshd_enabled_action:testaction:1</ocil:test_action_ref>385055 ············<ocil:test_action_ref>ocil:ssg-sebool_daemons_dump_core_action:testaction:1</ocil:test_action_ref>
385056 ··········</ocil:actions>385056 ··········</ocil:actions>
385057 ········</ocil:questionnaire>385057 ········</ocil:questionnaire>
385058 ········<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_rng_ocil:questionnaire:1">385058 ········<ocil:questionnaire·id="ocil:ssg-sebool_domain_kernel_load_modules_ocil:questionnaire:1">
385059 ··········<ocil:title>SSH·server·uses·strong·entropy·to·seed</ocil:title>385059 ··········<ocil:title>Disable·the·domain_kernel_load_modules·SELinux·Boolean</ocil:title>
385060 ··········<ocil:actions>385060 ··········<ocil:actions>
385061 ············<ocil:test_action_ref>ocil:ssg-sshd_use_strong_rng_action:testaction:1</ocil:test_action_ref>385061 ············<ocil:test_action_ref>ocil:ssg-sebool_domain_kernel_load_modules_action:testaction:1</ocil:test_action_ref>
385062 ··········</ocil:actions>385062 ··········</ocil:actions>
385063 ········</ocil:questionnaire>385063 ········</ocil:questionnaire>
385064 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_at_allow_ocil:questionnaire:1">385064 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_rds_disabled_ocil:questionnaire:1">
385065 ··········<ocil:title>Verify·Group·Who·Owns·/etc/at.allow·file</ocil:title>385065 ··········<ocil:title>Disable·RDS·Support</ocil:title>
Max diff block lines reached; 3576158/3586809 bytes (99.70%) of diff not shown.
3.28 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ocil.xml
3.28 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ocil.xml
Ordering differences only
    
Offset 3, 12326 lines modifiedOffset 3, 12326 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-nfs_no_anonymous_ocil:questionnaire:1">
11 ······<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>11 ······<ocil:title>Specify·UID·and·GID·for·Anonymous·NFS·Connections</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-nfs_no_anonymous_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-package_tftp_removed_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1">
17 ······<ocil:title>Remove·tftp·Daemon</ocil:title>17 ······<ocil:title>Verify·Permissions·on·/etc/at.allow·file</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_tftp_removed_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_at_allow_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-ldap_client_start_tls_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-audit_ospp_general_ocil:questionnaire:1">
23 ······<ocil:title>Configure·LDAP·Client·to·Use·TLS·For·All·Transactions</ocil:title>23 ······<ocil:title>Perform·general·configuration·of·Audit·for·OSPP</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-ldap_client_start_tls_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-audit_ospp_general_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-service_sshd_enabled_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sebool_daemons_dump_core_ocil:questionnaire:1">
29 ······<ocil:title>Enable·the·OpenSSH·Service</ocil:title>29 ······<ocil:title>Disable·the·daemons_dump_core·SELinux·Boolean</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-service_sshd_enabled_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sebool_daemons_dump_core_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_rng_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sebool_domain_kernel_load_modules_ocil:questionnaire:1">
35 ······<ocil:title>SSH·server·uses·strong·entropy·to·seed</ocil:title>35 ······<ocil:title>Disable·the·domain_kernel_load_modules·SELinux·Boolean</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sshd_use_strong_rng_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sebool_domain_kernel_load_modules_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_at_allow_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_rds_disabled_ocil:questionnaire:1">
41 ······<ocil:title>Verify·Group·Who·Owns·/etc/at.allow·file</ocil:title>41 ······<ocil:title>Disable·RDS·Support</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_at_allow_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kernel_module_rds_disabled_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_shells_ocil:questionnaire:1"> 
47 ······<ocil:title>Verify·Group·Who·Owns·/etc/shells·File</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1">
 47 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_shells_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_owner_change_success_ocil:questionnaire:1"> 
53 ······<ocil:title>Configure·auditing·of·successful·ownership·changes</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_ocil:questionnaire:1">
 53 ······<ocil:title>Configure·Accepting·Prefix·Information·in·Router·Advertisements·on·All·IPv6·Interfaces·By·Default</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_owner_change_success_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
59 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-no_host_based_files_ocil:questionnaire:1">
 59 ······<ocil:title>Remove·Host-Based·Authentication·Files</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-no_host_based_files_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1"> 
65 ······<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-sebool_httpd_dbus_avahi_ocil:questionnaire:1">
 65 ······<ocil:title>Disable·the·httpd_dbus_avahi·SELinux·Boolean</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sebool_httpd_dbus_avahi_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dcredit_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Digit·Characters</ocil:title>71 ······<ocil:title>Disable·IPv6·Addressing·on·All·IPv6·Interfaces</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dcredit_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sebool_virt_use_rawip_ocil:questionnaire:1"> 
77 ······<ocil:title>Disable·the·virt_use_rawip·SELinux·Boolean</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-directory_group_ownership_var_log_audit_ocil:questionnaire:1">
 77 ······<ocil:title>System·Audit·Directories·Must·Be·Group·Owned·By·Root</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sebool_virt_use_rawip_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-directory_group_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-set_firewalld_appropriate_zone_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sebool_xen_use_nfs_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·network·interfaces·are·assigned·to·appropriate·zone</ocil:title>83 ······<ocil:title>Disable·the·xen_use_nfs·SELinux·Boolean</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-set_firewalld_appropriate_zone_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sebool_xen_use_nfs_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_module_load_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1">
89 ······<ocil:title>Configure·auditing·of·loading·and·unloading·of·kernel·modules</ocil:title>89 ······<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_module_load_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_rsync_removed_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-aide_use_fips_hashes_ocil:questionnaire:1">
95 ······<ocil:title>Uninstall·rsync·Package</ocil:title>95 ······<ocil:title>Configure·AIDE·to·Use·FIPS·140-2·for·Validating·Hashes</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_rsync_removed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-aide_use_fips_hashes_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-service_pcscd_enabled_ocil:questionnaire:1"> 
101 ······<ocil:title>Enable·the·pcscd·Service</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-package_abrt-plugin-logger_removed_ocil:questionnaire:1">
 101 ······<ocil:title>Uninstall·abrt-plugin-logger·Package</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-service_pcscd_enabled_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-package_abrt-plugin-logger_removed_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-harden_sshd_ciphers_opensshserver_conf_crypto_policy_ocil:questionnaire:1"> 
107 ······<ocil:title>Configure·SSH·Server·to·Use·FIPS·140-2·Validated·Ciphers:·opensshserver.config</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_stig_ocil:questionnaire:1">
 107 ······<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-harden_sshd_ciphers_opensshserver_conf_crypto_policy_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_stig_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-gid_passwd_group_same_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">
113 ······<ocil:title>All·GIDs·referenced·in·/etc/passwd·must·be·defined·in·/etc/group</ocil:title>113 ······<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-gid_passwd_group_same_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-sebool_ftpd_use_nfs_ocil:questionnaire:1">
119 ······<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title>119 ······<ocil:title>Disable·the·ftpd_use_nfs·SELinux·Boolean</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-sebool_ftpd_use_nfs_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 3424160/3436441 bytes (99.64%) of diff not shown.
2.29 KB
./usr/share/xml/scap/ssg/content/ssg-rhel8-xccdf.xml
2.19 KB
./usr/share/xml/scap/ssg/content/ssg-rhel8-xccdf.xml
Ordering differences only
    
Offset 357, 25 lines modifiedOffset 357, 25 lines modified
357 ······</cpe-lang:logical-test>357 ······</cpe-lang:logical-test>
358 ····</cpe-lang:platform>358 ····</cpe-lang:platform>
359 ····<cpe-lang:platform·id="package_bash">359 ····<cpe-lang:platform·id="package_bash">
360 ······<cpe-lang:logical-test·operator="AND"·negate="false">360 ······<cpe-lang:logical-test·operator="AND"·negate="false">
361 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>361 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
362 ······</cpe-lang:logical-test>362 ······</cpe-lang:logical-test>
363 ····</cpe-lang:platform>363 ····</cpe-lang:platform>
364 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
365 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
366 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
367 ······</cpe-lang:logical-test> 
368 ····</cpe-lang:platform> 
369 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">364 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
370 ······<cpe-lang:logical-test·operator="AND"·negate="false">365 ······<cpe-lang:logical-test·operator="AND"·negate="false">
371 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>366 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
372 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>367 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
373 ······</cpe-lang:logical-test>368 ······</cpe-lang:logical-test>
374 ····</cpe-lang:platform>369 ····</cpe-lang:platform>
 370 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 371 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 372 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 373 ······</cpe-lang:logical-test>
 374 ····</cpe-lang:platform>
375 ····<cpe-lang:platform·id="not_s390x_arch">375 ····<cpe-lang:platform·id="not_s390x_arch">
376 ······<cpe-lang:logical-test·operator="AND"·negate="false">376 ······<cpe-lang:logical-test·operator="AND"·negate="false">
377 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>377 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
378 ······</cpe-lang:logical-test>378 ······</cpe-lang:logical-test>
379 ····</cpe-lang:platform>379 ····</cpe-lang:platform>
380 ····<cpe-lang:platform·id="package_tmux">380 ····<cpe-lang:platform·id="package_tmux">
381 ······<cpe-lang:logical-test·operator="AND"·negate="false">381 ······<cpe-lang:logical-test·operator="AND"·negate="false">
3.27 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
3.27 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of40 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 379, 25 lines modifiedOffset 379, 25 lines modified
379 ··········</cpe-lang:logical-test>379 ··········</cpe-lang:logical-test>
380 ········</cpe-lang:platform>380 ········</cpe-lang:platform>
381 ········<cpe-lang:platform·id="package_bash">381 ········<cpe-lang:platform·id="package_bash">
382 ··········<cpe-lang:logical-test·operator="AND"·negate="false">382 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
383 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>383 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
384 ··········</cpe-lang:logical-test>384 ··········</cpe-lang:logical-test>
385 ········</cpe-lang:platform>385 ········</cpe-lang:platform>
386 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
387 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
388 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
389 ··········</cpe-lang:logical-test> 
390 ········</cpe-lang:platform> 
391 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">386 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
392 ··········<cpe-lang:logical-test·operator="AND"·negate="false">387 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
393 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>388 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
394 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>389 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
395 ··········</cpe-lang:logical-test>390 ··········</cpe-lang:logical-test>
396 ········</cpe-lang:platform>391 ········</cpe-lang:platform>
 392 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 393 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 394 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 395 ··········</cpe-lang:logical-test>
 396 ········</cpe-lang:platform>
397 ········<cpe-lang:platform·id="not_s390x_arch">397 ········<cpe-lang:platform·id="not_s390x_arch">
398 ··········<cpe-lang:logical-test·operator="AND"·negate="false">398 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
399 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>399 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
400 ··········</cpe-lang:logical-test>400 ··········</cpe-lang:logical-test>
401 ········</cpe-lang:platform>401 ········</cpe-lang:platform>
402 ········<cpe-lang:platform·id="package_tmux">402 ········<cpe-lang:platform·id="package_tmux">
403 ··········<cpe-lang:logical-test·operator="AND"·negate="false">403 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 310419, 15 lines modifiedOffset 310419, 15 lines modified
310419 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>310419 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
310420 ············</xccdf-1.2:check>310420 ············</xccdf-1.2:check>
310421 ··········</xccdf-1.2:Rule>310421 ··········</xccdf-1.2:Rule>
310422 ········</xccdf-1.2:Group>310422 ········</xccdf-1.2:Group>
310423 ······</xccdf-1.2:Group>310423 ······</xccdf-1.2:Group>
310424 ····</xccdf-1.2:Benchmark>310424 ····</xccdf-1.2:Benchmark>
310425 ··</ds:component>310425 ··</ds:component>
310426 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-02-28T20:08:00">310426 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-03-01T22:08:00">
310427 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">310427 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
310428 ······<oval-def:generator>310428 ······<oval-def:generator>
310429 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>310429 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
310430 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>310430 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
310431 ········<oval:schema_version>5.11</oval:schema_version>310431 ········<oval:schema_version>5.11</oval:schema_version>
310432 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>310432 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
310433 ······</oval-def:generator>310433 ······</oval-def:generator>
Offset 377198, 11147 lines modifiedOffset 377198, 11147 lines modified
377198 ············</oval-def:arithmetic>377198 ············</oval-def:arithmetic>
377199 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>377199 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
377200 ··········</oval-def:arithmetic>377200 ··········</oval-def:arithmetic>
377201 ········</oval-def:local_variable>377201 ········</oval-def:local_variable>
377202 ······</oval-def:variables>377202 ······</oval-def:variables>
377203 ····</oval-def:oval_definitions>377203 ····</oval-def:oval_definitions>
377204 ··</ds:component>377204 ··</ds:component>
377205 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-02-28T20:08:00">377205 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-03-01T22:08:00">
377206 ····<ocil:ocil>377206 ····<ocil:ocil>
377207 ······<ocil:generator>377207 ······<ocil:generator>
377208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>377208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
377209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>377209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
377210 ········<ocil:schema_version>2.0</ocil:schema_version>377210 ········<ocil:schema_version>2.0</ocil:schema_version>
377211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>377211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
377212 ······</ocil:generator>377212 ······</ocil:generator>
377213 ······<ocil:questionnaires>377213 ······<ocil:questionnaires>
377214 ········<ocil:questionnaire·id="ocil:ssg-zipl_bls_entries_only_ocil:questionnaire:1"> 
377215 ··········<ocil:title>Ensure·all·zIPL·boot·entries·are·BLS·compliant</ocil:title> 
377216 ··········<ocil:actions> 
377217 ············<ocil:test_action_ref>ocil:ssg-zipl_bls_entries_only_action:testaction:1</ocil:test_action_ref> 
377218 ··········</ocil:actions> 
377219 ········</ocil:questionnaire> 
377220 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_shells_ocil:questionnaire:1">377214 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1">
377221 ··········<ocil:title>Verify·Who·Owns·/etc/shells·File</ocil:title>377215 ··········<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title>
377222 ··········<ocil:actions>377216 ··········<ocil:actions>
377223 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_shells_action:testaction:1</ocil:test_action_ref>377217 ············<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>
377224 ··········</ocil:actions>377218 ··········</ocil:actions>
377225 ········</ocil:questionnaire>377219 ········</ocil:questionnaire>
377226 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sudoers_ocil:questionnaire:1">377220 ········<ocil:questionnaire·id="ocil:ssg-sebool_httpd_enable_cgi_ocil:questionnaire:1">
377227 ··········<ocil:title>Verify·Group·Who·Owns·/etc/sudoers·File</ocil:title>377221 ··········<ocil:title>Configure·the·httpd_enable_cgi·SELinux·Boolean</ocil:title>
377228 ··········<ocil:actions>377222 ··········<ocil:actions>
377229 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sudoers_action:testaction:1</ocil:test_action_ref>377223 ············<ocil:test_action_ref>ocil:ssg-sebool_httpd_enable_cgi_action:testaction:1</ocil:test_action_ref>
377230 ··········</ocil:actions>377224 ··········</ocil:actions>
377231 ········</ocil:questionnaire>377225 ········</ocil:questionnaire>
377232 ········<ocil:questionnaire·id="ocil:ssg-mount_option_boot_efi_nosuid_ocil:questionnaire:1">377226 ········<ocil:questionnaire·id="ocil:ssg-configure_kerberos_crypto_policy_ocil:questionnaire:1">
377233 ··········<ocil:title>Add·nosuid·Option·to·/boot/efi</ocil:title>377227 ··········<ocil:title>Configure·Kerberos·to·use·System·Crypto·Policy</ocil:title>
377234 ··········<ocil:actions>377228 ··········<ocil:actions>
377235 ············<ocil:test_action_ref>ocil:ssg-mount_option_boot_efi_nosuid_action:testaction:1</ocil:test_action_ref>377229 ············<ocil:test_action_ref>ocil:ssg-configure_kerberos_crypto_policy_action:testaction:1</ocil:test_action_ref>
377236 ··········</ocil:actions>377230 ··········</ocil:actions>
377237 ········</ocil:questionnaire>377231 ········</ocil:questionnaire>
377238 ········<ocil:questionnaire·id="ocil:ssg-package_cryptsetup-luks_installed_ocil:questionnaire:1"> 
377239 ··········<ocil:title>Install·cryptsetup·Package</ocil:title>377232 ········<ocil:questionnaire·id="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1">
 377233 ··········<ocil:title>Ensure·SMEP·is·not·disabled·during·boot</ocil:title>
377240 ··········<ocil:actions>377234 ··········<ocil:actions>
377241 ············<ocil:test_action_ref>ocil:ssg-package_cryptsetup-luks_installed_action:testaction:1</ocil:test_action_ref>377235 ············<ocil:test_action_ref>ocil:ssg-grub2_nosmep_argument_absent_action:testaction:1</ocil:test_action_ref>
377242 ··········</ocil:actions>377236 ··········</ocil:actions>
377243 ········</ocil:questionnaire>377237 ········</ocil:questionnaire>
377244 ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_noexec_ocil:questionnaire:1">377238 ········<ocil:questionnaire·id="ocil:ssg-sebool_tftp_home_dir_ocil:questionnaire:1">
377245 ··········<ocil:title>Add·noexec·Option·to·/var/tmp</ocil:title>377239 ··········<ocil:title>Disable·the·tftp_home_dir·SELinux·Boolean</ocil:title>
377246 ··········<ocil:actions>377240 ··········<ocil:actions>
377247 ············<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_noexec_action:testaction:1</ocil:test_action_ref>377241 ············<ocil:test_action_ref>ocil:ssg-sebool_tftp_home_dir_action:testaction:1</ocil:test_action_ref>
377248 ··········</ocil:actions>377242 ··········</ocil:actions>
377249 ········</ocil:questionnaire>377243 ········</ocil:questionnaire>
377250 ········<ocil:questionnaire·id="ocil:ssg-sebool_dbadm_read_user_files_ocil:questionnaire:1">377244 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_allow_ocil:questionnaire:1">
377251 ··········<ocil:title>Disable·the·dbadm_read_user_files·SELinux·Boolean</ocil:title>377245 ··········<ocil:title>Verify·User·Who·Owns·/etc/cron.allow·file</ocil:title>
377252 ··········<ocil:actions>377246 ··········<ocil:actions>
Max diff block lines reached; 3422979/3433761 bytes (99.69%) of diff not shown.
3.14 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ocil.xml
3.14 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ocil.xml
Ordering differences only
    
Offset 3, 11138 lines modifiedOffset 3, 11138 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-zipl_bls_entries_only_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·all·zIPL·boot·entries·are·BLS·compliant</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-zipl_bls_entries_only_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_shells_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1">
17 ······<ocil:title>Verify·Who·Owns·/etc/shells·File</ocil:title>11 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_shells_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sudoers_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-sebool_httpd_enable_cgi_ocil:questionnaire:1">
23 ······<ocil:title>Verify·Group·Who·Owns·/etc/sudoers·File</ocil:title>17 ······<ocil:title>Configure·the·httpd_enable_cgi·SELinux·Boolean</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sudoers_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sebool_httpd_enable_cgi_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_efi_nosuid_ocil:questionnaire:1"> 
29 ······<ocil:title>Add·nosuid·Option·to·/boot/efi</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-configure_kerberos_crypto_policy_ocil:questionnaire:1">
 23 ······<ocil:title>Configure·Kerberos·to·use·System·Crypto·Policy</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_efi_nosuid_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-configure_kerberos_crypto_policy_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-package_cryptsetup-luks_installed_ocil:questionnaire:1"> 
35 ······<ocil:title>Install·cryptsetup·Package</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1">
 29 ······<ocil:title>Ensure·SMEP·is·not·disabled·during·boot</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-package_cryptsetup-luks_installed_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmep_argument_absent_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_noexec_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sebool_tftp_home_dir_ocil:questionnaire:1">
41 ······<ocil:title>Add·noexec·Option·to·/var/tmp</ocil:title>35 ······<ocil:title>Disable·the·tftp_home_dir·SELinux·Boolean</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_noexec_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sebool_tftp_home_dir_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sebool_dbadm_read_user_files_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_allow_ocil:questionnaire:1">
47 ······<ocil:title>Disable·the·dbadm_read_user_files·SELinux·Boolean</ocil:title>41 ······<ocil:title>Verify·User·Who·Owns·/etc/cron.allow·file</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sebool_dbadm_read_user_files_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_allow_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sebool_httpd_run_preupgrade_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-package_sssd_installed_ocil:questionnaire:1">
53 ······<ocil:title>Disable·the·httpd_run_preupgrade·SELinux·Boolean</ocil:title>47 ······<ocil:title>Install·the·SSSD·Package</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sebool_httpd_run_preupgrade_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-package_sssd_installed_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sebool_selinuxuser_tcp_server_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sebool_prosody_bind_http_port_ocil:questionnaire:1">
59 ······<ocil:title>Disable·the·selinuxuser_tcp_server·SELinux·Boolean</ocil:title>53 ······<ocil:title>Disable·the·prosody_bind_http_port·SELinux·Boolean</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_tcp_server_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sebool_prosody_bind_http_port_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sebool_openvpn_can_network_connect_ocil:questionnaire:1"> 
65 ······<ocil:title>Disable·the·openvpn_can_network_connect·SELinux·Boolean</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1">
 59 ······<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sebool_openvpn_can_network_connect_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_sestatus_conf_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1">
71 ······<ocil:title>Verify·User·Who·Owns·/etc/sestatus.conf·File</ocil:title>65 ······<ocil:title>System·Audit·Logs·Must·Have·Mode·0750·or·Less·Permissive</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-dir_group_ownership_library_dirs_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sestatus_conf_ocil:questionnaire:1">
77 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Group·Ownership</ocil:title>71 ······<ocil:title>Verify·Group·Who·Owns·/etc/sestatus.conf·File</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-dir_group_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nosuid_ocil:questionnaire:1"> 
83 ······<ocil:title>Add·nosuid·Option·to·/home</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy_ocil:questionnaire:1">
 77 ······<ocil:title>Configure·SSH·Client·to·Use·FIPS·140·Validated·Ciphers:·openssh.config</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nosuid_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sebool_ftpd_use_passive_mode_ocil:questionnaire:1"> 
89 ······<ocil:title>Disable·the·ftpd_use_passive_mode·SELinux·Boolean</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1">
 83 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sebool_ftpd_use_passive_mode_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_ocil:questionnaire:1"> 
95 ······<ocil:title>Configure·Accepting·Default·Router·in·Router·Advertisements·on·All·IPv6·Interfaces·By·Default</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-sebool_mozilla_plugin_use_bluejeans_ocil:questionnaire:1">
 89 ······<ocil:title>Disable·the·mozilla_plugin_use_bluejeans·SELinux·Boolean</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sebool_mozilla_plugin_use_bluejeans_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sebool_httpd_can_network_connect_ocil:questionnaire:1"> 
101 ······<ocil:title>Disable·the·httpd_can_network_connect·SELinux·Boolean</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1">
 95 ······<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sebool_httpd_can_network_connect_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sebool_postgresql_selinux_transmit_client_label_ocil:questionnaire:1"> 
107 ······<ocil:title>Disable·the·postgresql_selinux_transmit_client_label·SELinux·Boolean</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-accounts_users_home_files_permissions_ocil:questionnaire:1">
 101 ······<ocil:title>All·User·Files·and·Directories·In·The·Home·Directory·Must·Have·Mode·0750·Or·Less·Permissive</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sebool_postgresql_selinux_transmit_client_label_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-accounts_users_home_files_permissions_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1"> 
113 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·creat</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1">
 107 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_usermod_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·usermod</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-package_dnf-automatic_installed_ocil:questionnaire:1">
 113 ······<ocil:title>Install·dnf-automatic·Package</ocil:title>
Max diff block lines reached; 3279502/3291627 bytes (99.63%) of diff not shown.
2.29 KB
./usr/share/xml/scap/ssg/content/ssg-rhel9-xccdf.xml
2.19 KB
./usr/share/xml/scap/ssg/content/ssg-rhel9-xccdf.xml
Ordering differences only
    
Offset 346, 25 lines modifiedOffset 346, 25 lines modified
346 ······</cpe-lang:logical-test>346 ······</cpe-lang:logical-test>
347 ····</cpe-lang:platform>347 ····</cpe-lang:platform>
348 ····<cpe-lang:platform·id="package_bash">348 ····<cpe-lang:platform·id="package_bash">
349 ······<cpe-lang:logical-test·operator="AND"·negate="false">349 ······<cpe-lang:logical-test·operator="AND"·negate="false">
350 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>350 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
351 ······</cpe-lang:logical-test>351 ······</cpe-lang:logical-test>
352 ····</cpe-lang:platform>352 ····</cpe-lang:platform>
353 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
354 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
355 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
356 ······</cpe-lang:logical-test> 
357 ····</cpe-lang:platform> 
358 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">353 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
359 ······<cpe-lang:logical-test·operator="AND"·negate="false">354 ······<cpe-lang:logical-test·operator="AND"·negate="false">
360 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>355 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
361 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>356 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
362 ······</cpe-lang:logical-test>357 ······</cpe-lang:logical-test>
363 ····</cpe-lang:platform>358 ····</cpe-lang:platform>
 359 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 360 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 361 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 362 ······</cpe-lang:logical-test>
 363 ····</cpe-lang:platform>
364 ····<cpe-lang:platform·id="not_s390x_arch">364 ····<cpe-lang:platform·id="not_s390x_arch">
365 ······<cpe-lang:logical-test·operator="AND"·negate="false">365 ······<cpe-lang:logical-test·operator="AND"·negate="false">
366 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>366 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
367 ······</cpe-lang:logical-test>367 ······</cpe-lang:logical-test>
368 ····</cpe-lang:platform>368 ····</cpe-lang:platform>
369 ····<cpe-lang:platform·id="package_tmux">369 ····<cpe-lang:platform·id="package_tmux">
370 ······<cpe-lang:logical-test·operator="AND"·negate="false">370 ······<cpe-lang:logical-test·operator="AND"·negate="false">
1.57 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds.xml
1.57 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds.xml
    
Offset 19, 27 lines modifiedOffset 19, 27 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:enterprise_virtualization_manager:4">28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:enterprise_virtualization_manager:4">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Manager</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Manager</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_app_is_rhv4:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_app_is_rhv4:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8::hypervisor">32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8::hypervisor">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Host</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Host</cpe-dict:title>
34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_OS_is_rhv4:def:1</cpe-dict:check>34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_OS_is_rhv4:def:1</cpe-dict:check>
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ····</cpe-dict:cpe-list>36 ····</cpe-dict:cpe-list>
37 ··</ds:component>37 ··</ds:component>
38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-xccdf.xml"·timestamp="2025-02-28T20:08:00">38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-xccdf.xml"·timestamp="2025-03-01T22:08:00">
39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHV-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHV-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Virtualization·4</xccdf-1.2:title>41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Virtualization·4</xccdf-1.2:title>
42 ······<xccdf-1.2:description>42 ······<xccdf-1.2:description>
43 ········This·guide·presents·a·catalog·of·security-relevant43 ········This·guide·presents·a·catalog·of·security-relevant
44 configuration·settings·for·Red·Hat·Virtualization·4.·It·is·a·rendering·of44 configuration·settings·for·Red·Hat·Virtualization·4.·It·is·a·rendering·of
45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 162832, 15 lines modifiedOffset 162832, 15 lines modified
162832 ··············<xccdf-1.2:check-content-ref·href="ssg-rhv4-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>162832 ··············<xccdf-1.2:check-content-ref·href="ssg-rhv4-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
162833 ············</xccdf-1.2:check>162833 ············</xccdf-1.2:check>
162834 ··········</xccdf-1.2:Rule>162834 ··········</xccdf-1.2:Rule>
162835 ········</xccdf-1.2:Group>162835 ········</xccdf-1.2:Group>
162836 ······</xccdf-1.2:Group>162836 ······</xccdf-1.2:Group>
162837 ····</xccdf-1.2:Benchmark>162837 ····</xccdf-1.2:Benchmark>
162838 ··</ds:component>162838 ··</ds:component>
162839 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-oval.xml"·timestamp="2025-02-28T20:08:00">162839 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-oval.xml"·timestamp="2025-03-01T22:08:00">
162840 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">162840 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
162841 ······<oval-def:generator>162841 ······<oval-def:generator>
162842 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>162842 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
162843 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>162843 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
162844 ········<oval:schema_version>5.11</oval:schema_version>162844 ········<oval:schema_version>5.11</oval:schema_version>
162845 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>162845 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
162846 ······</oval-def:generator>162846 ······</oval-def:generator>
Offset 195359, 6676 lines modifiedOffset 195359, 6676 lines modified
195359 ············</oval-def:arithmetic>195359 ············</oval-def:arithmetic>
195360 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>195360 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
195361 ··········</oval-def:arithmetic>195361 ··········</oval-def:arithmetic>
195362 ········</oval-def:local_variable>195362 ········</oval-def:local_variable>
195363 ······</oval-def:variables>195363 ······</oval-def:variables>
195364 ····</oval-def:oval_definitions>195364 ····</oval-def:oval_definitions>
195365 ··</ds:component>195365 ··</ds:component>
195366 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-ocil.xml"·timestamp="2025-02-28T20:08:00">195366 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-ocil.xml"·timestamp="2025-03-01T22:08:00">
195367 ····<ocil:ocil>195367 ····<ocil:ocil>
195368 ······<ocil:generator>195368 ······<ocil:generator>
195369 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>195369 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
195370 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>195370 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
195371 ········<ocil:schema_version>2.0</ocil:schema_version>195371 ········<ocil:schema_version>2.0</ocil:schema_version>
195372 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>195372 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
195373 ······</ocil:generator>195373 ······</ocil:generator>
195374 ······<ocil:questionnaires>195374 ······<ocil:questionnaires>
195375 ········<ocil:questionnaire·id="ocil:ssg-configure_libreswan_crypto_policy_ocil:questionnaire:1">195375 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">
195376 ··········<ocil:title>Configure·Libreswan·to·use·System·Crypto·Policy</ocil:title>195376 ··········<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>
195377 ··········<ocil:actions>195377 ··········<ocil:actions>
195378 ············<ocil:test_action_ref>ocil:ssg-configure_libreswan_crypto_policy_action:testaction:1</ocil:test_action_ref>195378 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>
195379 ··········</ocil:actions>195379 ··········</ocil:actions>
195380 ········</ocil:questionnaire>195380 ········</ocil:questionnaire>
195381 ········<ocil:questionnaire·id="ocil:ssg-mount_option_noexec_remote_filesystems_ocil:questionnaire:1">195381 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">
195382 ··········<ocil:title>Mount·Remote·Filesystems·with·noexec</ocil:title>195382 ··········<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>
195383 ··········<ocil:actions>195383 ··········<ocil:actions>
195384 ············<ocil:test_action_ref>ocil:ssg-mount_option_noexec_remote_filesystems_action:testaction:1</ocil:test_action_ref>195384 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>
195385 ··········</ocil:actions>195385 ··········</ocil:actions>
195386 ········</ocil:questionnaire>195386 ········</ocil:questionnaire>
195387 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1"> 
195388 ··········<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title>195387 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1">
 195388 ··········<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
195389 ··········<ocil:actions>195389 ··········<ocil:actions>
195390 ············<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref>195390 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref>
195391 ··········</ocil:actions>195391 ··········</ocil:actions>
195392 ········</ocil:questionnaire>195392 ········</ocil:questionnaire>
195393 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1">195393 ········<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1">
195394 ··········<ocil:title>Disable·IPv6·Networking·Support·Automatic·Loading</ocil:title>195394 ··········<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>
195395 ··········<ocil:actions>195395 ··········<ocil:actions>
195396 ············<ocil:test_action_ref>ocil:ssg-kernel_module_ipv6_option_disabled_action:testaction:1</ocil:test_action_ref>195396 ············<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>
195397 ··········</ocil:actions>195397 ··········</ocil:actions>
195398 ········</ocil:questionnaire>195398 ········</ocil:questionnaire>
195399 ········<ocil:questionnaire·id="ocil:ssg-grub2_ipv6_disable_argument_ocil:questionnaire:1">195399 ········<ocil:questionnaire·id="ocil:ssg-package_xinetd_removed_ocil:questionnaire:1">
195400 ··········<ocil:title>Ensure·IPv6·is·disabled·through·kernel·boot·parameter</ocil:title>195400 ··········<ocil:title>Uninstall·xinetd·Package</ocil:title>
195401 ··········<ocil:actions>195401 ··········<ocil:actions>
195402 ············<ocil:test_action_ref>ocil:ssg-grub2_ipv6_disable_argument_action:testaction:1</ocil:test_action_ref>195402 ············<ocil:test_action_ref>ocil:ssg-package_xinetd_removed_action:testaction:1</ocil:test_action_ref>
195403 ··········</ocil:actions>195403 ··········</ocil:actions>
195404 ········</ocil:questionnaire>195404 ········</ocil:questionnaire>
195405 ········<ocil:questionnaire·id="ocil:ssg-file_permission_user_init_files_ocil:questionnaire:1">195405 ········<ocil:questionnaire·id="ocil:ssg-sebool_logadm_exec_content_ocil:questionnaire:1">
195406 ··········<ocil:title>Ensure·All·User·Initialization·Files·Have·Mode·0740·Or·Less·Permissive</ocil:title>195406 ··········<ocil:title>Enable·the·logadm_exec_content·SELinux·Boolean</ocil:title>
195407 ··········<ocil:actions>195407 ··········<ocil:actions>
195408 ············<ocil:test_action_ref>ocil:ssg-file_permission_user_init_files_action:testaction:1</ocil:test_action_ref>195408 ············<ocil:test_action_ref>ocil:ssg-sebool_logadm_exec_content_action:testaction:1</ocil:test_action_ref>
195409 ··········</ocil:actions>195409 ··········</ocil:actions>
195410 ········</ocil:questionnaire>195410 ········</ocil:questionnaire>
195411 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">195411 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1">
195412 ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>195412 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
195413 ··········<ocil:actions>195413 ··········<ocil:actions>
195414 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>195414 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref>
195415 ··········</ocil:actions>195415 ··········</ocil:actions>
195416 ········</ocil:questionnaire>195416 ········</ocil:questionnaire>
195417 ········<ocil:questionnaire·id="ocil:ssg-sshd_rekey_limit_ocil:questionnaire:1">195417 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1">
195418 ··········<ocil:title>Force·frequent·session·key·renegotiation</ocil:title>195418 ··········<ocil:title>Set·Password·Warning·Age</ocil:title>
195419 ··········<ocil:actions>195419 ··········<ocil:actions>
195420 ············<ocil:test_action_ref>ocil:ssg-sshd_rekey_limit_action:testaction:1</ocil:test_action_ref>195420 ············<ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref>
195421 ··········</ocil:actions>195421 ··········</ocil:actions>
195422 ········</ocil:questionnaire>195422 ········</ocil:questionnaire>
195423 ········<ocil:questionnaire·id="ocil:ssg-service_rsyncd_disabled_ocil:questionnaire:1">195423 ········<ocil:questionnaire·id="ocil:ssg-harden_ssh_client_crypto_policy_ocil:questionnaire:1">
195424 ··········<ocil:title>Ensure·rsyncd·service·is·disabled</ocil:title>195424 ··········<ocil:title>Harden·SSH·client·Crypto·Policy</ocil:title>
195425 ··········<ocil:actions>195425 ··········<ocil:actions>
195426 ············<ocil:test_action_ref>ocil:ssg-service_rsyncd_disabled_action:testaction:1</ocil:test_action_ref>195426 ············<ocil:test_action_ref>ocil:ssg-harden_ssh_client_crypto_policy_action:testaction:1</ocil:test_action_ref>
195427 ··········</ocil:actions>195427 ··········</ocil:actions>
195428 ········</ocil:questionnaire>195428 ········</ocil:questionnaire>
195429 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_ocil:questionnaire:1"> 
195430 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open_by_handle_at</ocil:title>195429 ········<ocil:questionnaire·id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1">
 195430 ··········<ocil:title>Ensure·the·Logon·Failure·Delay·is·Set·Correctly·in·login.defs</ocil:title>
195431 ··········<ocil:actions>195431 ··········<ocil:actions>
195432 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_action:testaction:1</ocil:test_action_ref>195432 ············<ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>
195433 ··········</ocil:actions>195433 ··········</ocil:actions>
195434 ········</ocil:questionnaire>195434 ········</ocil:questionnaire>
195435 ········<ocil:questionnaire·id="ocil:ssg-sssd_offline_cred_expiration_ocil:questionnaire:1">195435 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_stig_ocil:questionnaire:1">
195436 ··········<ocil:title>Configure·SSSD·to·Expire·Offline·Credentials</ocil:title>195436 ··········<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title>
195437 ··········<ocil:actions>195437 ··········<ocil:actions>
195438 ············<ocil:test_action_ref>ocil:ssg-sssd_offline_cred_expiration_action:testaction:1</ocil:test_action_ref>195438 ············<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_stig_action:testaction:1</ocil:test_action_ref>
195439 ··········</ocil:actions>195439 ··········</ocil:actions>
Max diff block lines reached; 1635735/1647972 bytes (99.26%) of diff not shown.
1.5 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ocil.xml
1.5 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ocil.xml
Ordering differences only
    
Offset 3, 6667 lines modifiedOffset 3, 6667 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-configure_libreswan_crypto_policy_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">
11 ······<ocil:title>Configure·Libreswan·to·use·System·Crypto·Policy</ocil:title>11 ······<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-configure_libreswan_crypto_policy_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-mount_option_noexec_remote_filesystems_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">
17 ······<ocil:title>Mount·Remote·Filesystems·with·noexec</ocil:title>17 ······<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-mount_option_noexec_remote_filesystems_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1"> 
23 ······<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1">
 23 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1">
29 ······<ocil:title>Disable·IPv6·Networking·Support·Automatic·Loading</ocil:title>29 ······<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_module_ipv6_option_disabled_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-grub2_ipv6_disable_argument_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-package_xinetd_removed_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·IPv6·is·disabled·through·kernel·boot·parameter</ocil:title>35 ······<ocil:title>Uninstall·xinetd·Package</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-grub2_ipv6_disable_argument_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-package_xinetd_removed_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_permission_user_init_files_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sebool_logadm_exec_content_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·All·User·Initialization·Files·Have·Mode·0740·Or·Less·Permissive</ocil:title>41 ······<ocil:title>Enable·the·logadm_exec_content·SELinux·Boolean</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_permission_user_init_files_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sebool_logadm_exec_content_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1">
47 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>47 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sshd_rekey_limit_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1">
53 ······<ocil:title>Force·frequent·session·key·renegotiation</ocil:title>53 ······<ocil:title>Set·Password·Warning·Age</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sshd_rekey_limit_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-service_rsyncd_disabled_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-harden_ssh_client_crypto_policy_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·rsyncd·service·is·disabled</ocil:title>59 ······<ocil:title>Harden·SSH·client·Crypto·Policy</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-service_rsyncd_disabled_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-harden_ssh_client_crypto_policy_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_ocil:questionnaire:1"> 
65 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open_by_handle_at</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1">
 65 ······<ocil:title>Ensure·the·Logon·Failure·Delay·is·Set·Correctly·in·login.defs</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sssd_offline_cred_expiration_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_stig_ocil:questionnaire:1">
71 ······<ocil:title>Configure·SSSD·to·Expire·Offline·Credentials</ocil:title>71 ······<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sssd_offline_cred_expiration_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_stig_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nosuid_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_nopasswd_ocil:questionnaire:1">
77 ······<ocil:title>Add·nosuid·Option·to·/dev/shm</ocil:title>77 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·NOPASSWD</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nosuid_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_nopasswd_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_d_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Group·Who·Owns·cron.d</ocil:title>83 ······<ocil:title>Ensure·gpgcheck·Enabled·In·Main·yum·Configuration</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_d_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwquality_password_auth_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-accounts_tmout_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·PAM·password·complexity·module·is·enabled·in·password-auth</ocil:title>89 ······<ocil:title>Set·Interactive·Session·Timeout</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwquality_password_auth_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-accounts_tmout_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1">
95 ······<ocil:title>Disable·Accepting·Packets·Routed·Between·Local·Interfaces</ocil:title>95 ······<ocil:title>Disable·GSSAPI·Authentication</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_gssapi_auth_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-selinux_policytype_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sebool_sysadm_exec_content_ocil:questionnaire:1">
101 ······<ocil:title>Configure·SELinux·Policy</ocil:title>101 ······<ocil:title>Enable·the·sysadm_exec_content·SELinux·Boolean</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-selinux_policytype_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sebool_sysadm_exec_content_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_ocil:questionnaire:1"> 
107 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-clean_components_post_updating_ocil:questionnaire:1">
 107 ······<ocil:title>Ensure·yum·Removes·Previous·Package·Versions</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-clean_components_post_updating_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-no_rsh_trust_files_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-sebool_logging_syslogd_use_tty_ocil:questionnaire:1">
113 ······<ocil:title>Remove·Rsh·Trust·Files</ocil:title>113 ······<ocil:title>Enable·the·logging_syslogd_use_tty·SELinux·Boolean</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-no_rsh_trust_files_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sebool_logging_syslogd_use_tty_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1"> 
119 ······<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_vdso_ocil:questionnaire:1">
 119 ······<ocil:title>Disable·the·32-bit·vDSO</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-kernel_config_compat_vdso_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-package_telnet-server_removed_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">
125 ······<ocil:title>Uninstall·telnet-server·Package</ocil:title>125 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>
Max diff block lines reached; 1562697/1575529 bytes (99.19%) of diff not shown.
1.79 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds.xml
1.79 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds.xml
    
Offset 21, 27 lines modifiedOffset 21, 27 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.12-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.12-patch.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.12-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.12-patch.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:12">30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:12">
31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·12</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·12</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:12">34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:12">
35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·12</cpe-dict:title>35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·12</cpe-dict:title>
36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>
37 ······</cpe-dict:cpe-item>37 ······</cpe-dict:cpe-item>
38 ····</cpe-dict:cpe-list>38 ····</cpe-dict:cpe-list>
39 ··</ds:component>39 ··</ds:component>
40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-xccdf.xml"·timestamp="2025-02-28T20:08:00">40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-xccdf.xml"·timestamp="2025-03-01T22:08:00">
41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·12</xccdf-1.2:title>43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·12</xccdf-1.2:title>
44 ······<xccdf-1.2:description>44 ······<xccdf-1.2:description>
45 ········This·guide·presents·a·catalog·of·security-relevant45 ········This·guide·presents·a·catalog·of·security-relevant
46 configuration·settings·for·SUSE·Linux·Enterprise·12.·It·is·a·rendering·of46 configuration·settings·for·SUSE·Linux·Enterprise·12.·It·is·a·rendering·of
47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 329, 23 lines modifiedOffset 329, 23 lines modified
329 ··········</cpe-lang:logical-test>329 ··········</cpe-lang:logical-test>
330 ········</cpe-lang:platform>330 ········</cpe-lang:platform>
331 ········<cpe-lang:platform·id="package_bash">331 ········<cpe-lang:platform·id="package_bash">
332 ··········<cpe-lang:logical-test·operator="AND"·negate="false">332 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
333 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>333 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
334 ··········</cpe-lang:logical-test>334 ··········</cpe-lang:logical-test>
335 ········</cpe-lang:platform>335 ········</cpe-lang:platform>
336 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">336 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
337 ··········<cpe-lang:logical-test·operator="AND"·negate="false">337 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
338 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>338 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
339 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
340 ··········</cpe-lang:logical-test>339 ··········</cpe-lang:logical-test>
341 ········</cpe-lang:platform>340 ········</cpe-lang:platform>
342 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">341 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
343 ··········<cpe-lang:logical-test·operator="AND"·negate="false">342 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
344 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>343 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 344 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
345 ··········</cpe-lang:logical-test>345 ··········</cpe-lang:logical-test>
346 ········</cpe-lang:platform>346 ········</cpe-lang:platform>
347 ········<cpe-lang:platform·id="not_s390x_arch">347 ········<cpe-lang:platform·id="not_s390x_arch">
348 ··········<cpe-lang:logical-test·operator="AND"·negate="false">348 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
349 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>349 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
350 ··········</cpe-lang:logical-test>350 ··········</cpe-lang:logical-test>
351 ········</cpe-lang:platform>351 ········</cpe-lang:platform>
Offset 186684, 15 lines modifiedOffset 186684, 15 lines modified
186684 ··············<xccdf-1.2:check-content-ref·href="ssg-sle12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>186684 ··············<xccdf-1.2:check-content-ref·href="ssg-sle12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
186685 ············</xccdf-1.2:check>186685 ············</xccdf-1.2:check>
186686 ··········</xccdf-1.2:Rule>186686 ··········</xccdf-1.2:Rule>
186687 ········</xccdf-1.2:Group>186687 ········</xccdf-1.2:Group>
186688 ······</xccdf-1.2:Group>186688 ······</xccdf-1.2:Group>
186689 ····</xccdf-1.2:Benchmark>186689 ····</xccdf-1.2:Benchmark>
186690 ··</ds:component>186690 ··</ds:component>
186691 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-oval.xml"·timestamp="2025-02-28T20:08:00">186691 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-oval.xml"·timestamp="2025-03-01T22:08:00">
186692 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">186692 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
186693 ······<oval-def:generator>186693 ······<oval-def:generator>
186694 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>186694 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
186695 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>186695 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
186696 ········<oval:schema_version>5.11</oval:schema_version>186696 ········<oval:schema_version>5.11</oval:schema_version>
186697 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>186697 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
186698 ······</oval-def:generator>186698 ······</oval-def:generator>
Offset 227001, 8065 lines modifiedOffset 227001, 8065 lines modified
227001 ············</oval-def:arithmetic>227001 ············</oval-def:arithmetic>
227002 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>227002 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
227003 ··········</oval-def:arithmetic>227003 ··········</oval-def:arithmetic>
227004 ········</oval-def:local_variable>227004 ········</oval-def:local_variable>
227005 ······</oval-def:variables>227005 ······</oval-def:variables>
227006 ····</oval-def:oval_definitions>227006 ····</oval-def:oval_definitions>
227007 ··</ds:component>227007 ··</ds:component>
227008 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-ocil.xml"·timestamp="2025-02-28T20:08:00">227008 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-ocil.xml"·timestamp="2025-03-01T22:08:00">
227009 ····<ocil:ocil>227009 ····<ocil:ocil>
227010 ······<ocil:generator>227010 ······<ocil:generator>
227011 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>227011 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
227012 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>227012 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
227013 ········<ocil:schema_version>2.0</ocil:schema_version>227013 ········<ocil:schema_version>2.0</ocil:schema_version>
227014 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>227014 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
227015 ······</ocil:generator>227015 ······</ocil:generator>
227016 ······<ocil:questionnaires>227016 ······<ocil:questionnaires>
227017 ········<ocil:questionnaire·id="ocil:ssg-accounts_set_post_pw_existing_ocil:questionnaire:1">227017 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_private_key_ocil:questionnaire:1">
227018 ··········<ocil:title>Set·existing·passwords·a·period·of·inactivity·before·they·been·locked</ocil:title>227018 ··········<ocil:title>Verify·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>
227019 ··········<ocil:actions>227019 ··········<ocil:actions>
227020 ············<ocil:test_action_ref>ocil:ssg-accounts_set_post_pw_existing_action:testaction:1</ocil:test_action_ref>227020 ············<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>
227021 ··········</ocil:actions>227021 ··········</ocil:actions>
227022 ········</ocil:questionnaire>227022 ········</ocil:questionnaire>
227023 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">227023 ········<ocil:questionnaire·id="ocil:ssg-package_avahi-autoipd_removed_ocil:questionnaire:1">
227024 ··········<ocil:title>Verify·Owner·on·cron.weekly</ocil:title>227024 ··········<ocil:title>Uninstall·avahi-autoipd·Server·Package</ocil:title>
227025 ··········<ocil:actions>227025 ··········<ocil:actions>
227026 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>227026 ············<ocil:test_action_ref>ocil:ssg-package_avahi-autoipd_removed_action:testaction:1</ocil:test_action_ref>
227027 ··········</ocil:actions>227027 ··········</ocil:actions>
227028 ········</ocil:questionnaire>227028 ········</ocil:questionnaire>
227029 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_ipsec_secrets_ocil:questionnaire:1">227029 ········<ocil:questionnaire·id="ocil:ssg-package_dhcp_removed_ocil:questionnaire:1">
227030 ··········<ocil:title>Verify·Group·Who·Owns·/etc/ipsec.secrets·File</ocil:title>227030 ··········<ocil:title>Uninstall·DHCP·Server·Package</ocil:title>
227031 ··········<ocil:actions>227031 ··········<ocil:actions>
227032 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_ipsec_secrets_action:testaction:1</ocil:test_action_ref>227032 ············<ocil:test_action_ref>ocil:ssg-package_dhcp_removed_action:testaction:1</ocil:test_action_ref>
227033 ··········</ocil:actions>227033 ··········</ocil:actions>
227034 ········</ocil:questionnaire>227034 ········</ocil:questionnaire>
227035 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_ocil:questionnaire:1"> 
227036 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</ocil:title>227035 ········<ocil:questionnaire·id="ocil:ssg-package_dhcp_client_removed_ocil:questionnaire:1">
 227036 ··········<ocil:title>Uninstall·DHCP·Client·Package</ocil:title>
227037 ··········<ocil:actions>227037 ··········<ocil:actions>
227038 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>227038 ············<ocil:test_action_ref>ocil:ssg-package_dhcp_client_removed_action:testaction:1</ocil:test_action_ref>
227039 ··········</ocil:actions>227039 ··········</ocil:actions>
227040 ········</ocil:questionnaire>227040 ········</ocil:questionnaire>
227041 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">227041 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1">
227042 ··········<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>227042 ··········<ocil:title>Verify·Permissions·on·/etc/at.allow·file</ocil:title>
227043 ··········<ocil:actions>227043 ··········<ocil:actions>
227044 ············<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>227044 ············<ocil:test_action_ref>ocil:ssg-file_permissions_at_allow_action:testaction:1</ocil:test_action_ref>
227045 ··········</ocil:actions>227045 ··········</ocil:actions>
227046 ········</ocil:questionnaire>227046 ········</ocil:questionnaire>
227047 ········<ocil:questionnaire·id="ocil:ssg-sudo_remove_nopasswd_ocil:questionnaire:1"> 
227048 ··········<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·NOPASSWD</ocil:title>227047 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1">
 227048 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title>
227049 ··········<ocil:actions>227049 ··········<ocil:actions>
227050 ············<ocil:test_action_ref>ocil:ssg-sudo_remove_nopasswd_action:testaction:1</ocil:test_action_ref>227050 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>
227051 ··········</ocil:actions>227051 ··········</ocil:actions>
227052 ········</ocil:questionnaire>227052 ········</ocil:questionnaire>
227053 ········<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1">227053 ········<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_selinux_ocil:questionnaire:1">
227054 ··········<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title>227054 ··········<ocil:title>Verify·User·Who·Owns·/etc/selinux·Directory</ocil:title>
227055 ··········<ocil:actions>227055 ··········<ocil:actions>
227056 ············<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref>227056 ············<ocil:test_action_ref>ocil:ssg-directory_owner_etc_selinux_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1862008/1874118 bytes (99.35%) of diff not shown.
1.71 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ocil.xml
1.71 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ocil.xml
Ordering differences only
    
Offset 3, 8056 lines modifiedOffset 3, 8056 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-accounts_set_post_pw_existing_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_private_key_ocil:questionnaire:1">
11 ······<ocil:title>Set·existing·passwords·a·period·of·inactivity·before·they·been·locked</ocil:title>11 ······<ocil:title>Verify·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-accounts_set_post_pw_existing_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-package_avahi-autoipd_removed_ocil:questionnaire:1">
17 ······<ocil:title>Verify·Owner·on·cron.weekly</ocil:title>17 ······<ocil:title>Uninstall·avahi-autoipd·Server·Package</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-package_avahi-autoipd_removed_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_ipsec_secrets_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-package_dhcp_removed_ocil:questionnaire:1">
23 ······<ocil:title>Verify·Group·Who·Owns·/etc/ipsec.secrets·File</ocil:title>23 ······<ocil:title>Uninstall·DHCP·Server·Package</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_ipsec_secrets_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-package_dhcp_removed_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_ocil:questionnaire:1"> 
29 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-package_dhcp_client_removed_ocil:questionnaire:1">
 29 ······<ocil:title>Uninstall·DHCP·Client·Package</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-package_dhcp_client_removed_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1">
35 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>35 ······<ocil:title>Verify·Permissions·on·/etc/at.allow·file</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_at_allow_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_nopasswd_ocil:questionnaire:1"> 
41 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·NOPASSWD</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1">
 41 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_nopasswd_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_selinux_ocil:questionnaire:1">
47 ······<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title>47 ······<ocil:title>Verify·User·Who·Owns·/etc/selinux·Directory</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-directory_owner_etc_selinux_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_default_mmap_min_addr_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-package_cups_removed_ocil:questionnaire:1">
53 ······<ocil:title>Configure·Low·Address·Space·To·Protect·From·User·Allocation</ocil:title>53 ······<ocil:title>Uninstall·CUPS·Package</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-kernel_config_default_mmap_min_addr_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-package_cups_removed_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">
59 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>59 ······<ocil:title>Enable·module·signature·verification</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1"> 
65 ······<ocil:title>Disable·Accepting·Router·Advertisements·on·all·IPv6·Interfaces·by·Default</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-no_legacy_plus_entries_etc_shadow_ocil:questionnaire:1">
 65 ······<ocil:title>Ensure·there·are·no·legacy·+·NIS·entries·in·/etc/shadow</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-no_legacy_plus_entries_etc_shadow_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_home_directories_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-service_dovecot_disabled_ocil:questionnaire:1">
71 ······<ocil:title>All·Interactive·User·Home·Directories·Must·Have·mode·0750·Or·Less·Permissive</ocil:title>71 ······<ocil:title>Disable·Dovecot·Service</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_home_directories_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-service_dovecot_disabled_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_nosuid_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_macs_ocil:questionnaire:1">
77 ······<ocil:title>Add·nosuid·Option·to·/var/log</ocil:title>77 ······<ocil:title>Use·Only·Strong·MACs</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_nosuid_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sshd_use_strong_macs_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-group_unique_id_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-gui_login_dod_acknowledgement_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·All·Groups·on·the·System·Have·Unique·Group·ID</ocil:title>83 ······<ocil:title>Display·the·Standard·Mandatory·DoD·Notice·and·Consent·Banner·until·Explicit·Acknowledgement</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-group_unique_id_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-gui_login_dod_acknowledgement_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_monthly_ocil:questionnaire:1">
89 ······<ocil:title>Deactivate·Wireless·Network·Interfaces</ocil:title>89 ······<ocil:title>Verify·Group·Who·Owns·cron.monthly</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_monthly_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-grub2_systemd_debug-shell_argument_absent_ocil:questionnaire:1"> 
95 ······<ocil:title>Ensure·debug-shell·service·is·not·enabled·during·boot</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1">
 95 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-grub2_systemd_debug-shell_argument_absent_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_passmass_ocil:questionnaire:1"> 
101 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·passmass</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1">
 101 ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_passmass_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_user_cfg_ocil:questionnaire:1"> 
107 ······<ocil:title>Verify·/boot/grub2/user.cfg·Permissions</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_ocil:questionnaire:1">
 107 ······<ocil:title>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_user_cfg_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_tcp_syncookies_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-susefirewall2_only_required_services_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-selinux_policytype_ocil:questionnaire:1">
113 ······<ocil:title>Only·Allow·Authorized·Network·Services·in·SuSEfirewall2</ocil:title>113 ······<ocil:title>Configure·SELinux·Policy</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-susefirewall2_only_required_services_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-selinux_policytype_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_etc_selinux_ocil:questionnaire:1"> 
119 ······<ocil:title>Verify·Permissions·On·/etc/selinux·Directory</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-package_openssh_removed_ocil:questionnaire:1">
 119 ······<ocil:title>Remove·the·OpenSSH·Client·and·Server·Package</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_etc_selinux_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-package_openssh_removed_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 1777148/1789792 bytes (99.29%) of diff not shown.
2.49 KB
./usr/share/xml/scap/ssg/content/ssg-sle12-xccdf.xml
2.39 KB
./usr/share/xml/scap/ssg/content/ssg-sle12-xccdf.xml
Ordering differences only
    
Offset 290, 23 lines modifiedOffset 290, 23 lines modified
290 ······</cpe-lang:logical-test>290 ······</cpe-lang:logical-test>
291 ····</cpe-lang:platform>291 ····</cpe-lang:platform>
292 ····<cpe-lang:platform·id="package_bash">292 ····<cpe-lang:platform·id="package_bash">
293 ······<cpe-lang:logical-test·operator="AND"·negate="false">293 ······<cpe-lang:logical-test·operator="AND"·negate="false">
294 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>294 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
295 ······</cpe-lang:logical-test>295 ······</cpe-lang:logical-test>
296 ····</cpe-lang:platform>296 ····</cpe-lang:platform>
297 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">297 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
298 ······<cpe-lang:logical-test·operator="AND"·negate="false">298 ······<cpe-lang:logical-test·operator="AND"·negate="false">
299 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>299 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
300 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
301 ······</cpe-lang:logical-test>300 ······</cpe-lang:logical-test>
302 ····</cpe-lang:platform>301 ····</cpe-lang:platform>
303 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">302 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
304 ······<cpe-lang:logical-test·operator="AND"·negate="false">303 ······<cpe-lang:logical-test·operator="AND"·negate="false">
305 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>304 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 305 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
306 ······</cpe-lang:logical-test>306 ······</cpe-lang:logical-test>
307 ····</cpe-lang:platform>307 ····</cpe-lang:platform>
308 ····<cpe-lang:platform·id="not_s390x_arch">308 ····<cpe-lang:platform·id="not_s390x_arch">
309 ······<cpe-lang:logical-test·operator="AND"·negate="false">309 ······<cpe-lang:logical-test·operator="AND"·negate="false">
310 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>310 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
311 ······</cpe-lang:logical-test>311 ······</cpe-lang:logical-test>
312 ····</cpe-lang:platform>312 ····</cpe-lang:platform>
1.88 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml
1.88 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml
    
Offset 21, 27 lines modifiedOffset 21, 27 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.15-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.15-patch.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.15-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.15-patch.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:15">30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:15">
31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·15</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·15</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:15">34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:15">
35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·15</cpe-dict:title>35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·15</cpe-dict:title>
36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>
37 ······</cpe-dict:cpe-item>37 ······</cpe-dict:cpe-item>
38 ····</cpe-dict:cpe-list>38 ····</cpe-dict:cpe-list>
39 ··</ds:component>39 ··</ds:component>
40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-xccdf.xml"·timestamp="2025-02-28T20:08:00">40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-xccdf.xml"·timestamp="2025-03-01T22:08:00">
41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-15"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-15"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·15</xccdf-1.2:title>43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·15</xccdf-1.2:title>
44 ······<xccdf-1.2:description>44 ······<xccdf-1.2:description>
45 ········This·guide·presents·a·catalog·of·security-relevant45 ········This·guide·presents·a·catalog·of·security-relevant
46 configuration·settings·for·SUSE·Linux·Enterprise·15.·It·is·a·rendering·of46 configuration·settings·for·SUSE·Linux·Enterprise·15.·It·is·a·rendering·of
47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 200277, 15 lines modifiedOffset 200277, 15 lines modified
200277 ··············<xccdf-1.2:check-content-ref·href="ssg-sle15-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>200277 ··············<xccdf-1.2:check-content-ref·href="ssg-sle15-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
200278 ············</xccdf-1.2:check>200278 ············</xccdf-1.2:check>
200279 ··········</xccdf-1.2:Rule>200279 ··········</xccdf-1.2:Rule>
200280 ········</xccdf-1.2:Group>200280 ········</xccdf-1.2:Group>
200281 ······</xccdf-1.2:Group>200281 ······</xccdf-1.2:Group>
200282 ····</xccdf-1.2:Benchmark>200282 ····</xccdf-1.2:Benchmark>
200283 ··</ds:component>200283 ··</ds:component>
200284 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-oval.xml"·timestamp="2025-02-28T20:08:00">200284 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-oval.xml"·timestamp="2025-03-01T22:08:00">
200285 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">200285 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
200286 ······<oval-def:generator>200286 ······<oval-def:generator>
200287 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>200287 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
200288 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>200288 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
200289 ········<oval:schema_version>5.11</oval:schema_version>200289 ········<oval:schema_version>5.11</oval:schema_version>
200290 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>200290 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
200291 ······</oval-def:generator>200291 ······</oval-def:generator>
Offset 242596, 8965 lines modifiedOffset 242596, 8965 lines modified
242596 ············</oval-def:arithmetic>242596 ············</oval-def:arithmetic>
242597 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>242597 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
242598 ··········</oval-def:arithmetic>242598 ··········</oval-def:arithmetic>
242599 ········</oval-def:local_variable>242599 ········</oval-def:local_variable>
242600 ······</oval-def:variables>242600 ······</oval-def:variables>
242601 ····</oval-def:oval_definitions>242601 ····</oval-def:oval_definitions>
242602 ··</ds:component>242602 ··</ds:component>
242603 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-ocil.xml"·timestamp="2025-02-28T20:08:00">242603 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-ocil.xml"·timestamp="2025-03-01T22:08:00">
242604 ····<ocil:ocil>242604 ····<ocil:ocil>
242605 ······<ocil:generator>242605 ······<ocil:generator>
242606 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>242606 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
242607 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>242607 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
242608 ········<ocil:schema_version>2.0</ocil:schema_version>242608 ········<ocil:schema_version>2.0</ocil:schema_version>
242609 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>242609 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
242610 ······</ocil:generator>242610 ······</ocil:generator>
242611 ······<ocil:questionnaires>242611 ······<ocil:questionnaires>
242612 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1"> 
242613 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title> 
242614 ··········<ocil:actions> 
242615 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref> 
242616 ··········</ocil:actions> 
242617 ········</ocil:questionnaire> 
242618 ········<ocil:questionnaire·id="ocil:ssg-no_files_unowned_by_user_ocil:questionnaire:1">242612 ········<ocil:questionnaire·id="ocil:ssg-service_snmpd_disabled_ocil:questionnaire:1">
 242613 ··········<ocil:title>Disable·snmpd·Service</ocil:title>
242619 ··········<ocil:title>Ensure·All·Files·Are·Owned·by·a·User</ocil:title> 
242620 ··········<ocil:actions> 
242621 ············<ocil:test_action_ref>ocil:ssg-no_files_unowned_by_user_action:testaction:1</ocil:test_action_ref> 
242622 ··········</ocil:actions> 
242623 ········</ocil:questionnaire> 
242624 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"> 
242625 ··········<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title> 
242626 ··········<ocil:actions>242614 ··········<ocil:actions>
242627 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>242615 ············<ocil:test_action_ref>ocil:ssg-service_snmpd_disabled_action:testaction:1</ocil:test_action_ref>
242628 ··········</ocil:actions>242616 ··········</ocil:actions>
242629 ········</ocil:questionnaire>242617 ········</ocil:questionnaire>
242630 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_rm_ocil:questionnaire:1">242618 ········<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">
242631 ··········<ocil:title>Record·Any·Attempts·to·Run·rm</ocil:title>242619 ··········<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>
242632 ··········<ocil:actions>242620 ··········<ocil:actions>
242633 ············<ocil:test_action_ref>ocil:ssg-audit_rules_execution_rm_action:testaction:1</ocil:test_action_ref>242621 ············<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>
242634 ··········</ocil:actions>242622 ··········</ocil:actions>
242635 ········</ocil:questionnaire>242623 ········</ocil:questionnaire>
242636 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_filter_ocil:questionnaire:1">242624 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">
242637 ··········<ocil:title>Enable·use·of·Berkeley·Packet·Filter·with·seccomp</ocil:title>242625 ··········<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>
242638 ··········<ocil:actions>242626 ··········<ocil:actions>
242639 ············<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_filter_action:testaction:1</ocil:test_action_ref>242627 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>
242640 ··········</ocil:actions>242628 ··········</ocil:actions>
242641 ········</ocil:questionnaire>242629 ········</ocil:questionnaire>
242642 ········<ocil:questionnaire·id="ocil:ssg-file_permission_user_init_files_ocil:questionnaire:1">242630 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_sgid_ocil:questionnaire:1">
242643 ··········<ocil:title>Ensure·All·User·Initialization·Files·Have·Mode·0740·Or·Less·Permissive</ocil:title>242631 ··········<ocil:title>Ensure·All·SGID·Executables·Are·Authorized</ocil:title>
242644 ··········<ocil:actions>242632 ··········<ocil:actions>
242645 ············<ocil:test_action_ref>ocil:ssg-file_permission_user_init_files_action:testaction:1</ocil:test_action_ref>242633 ············<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_sgid_action:testaction:1</ocil:test_action_ref>
242646 ··········</ocil:actions>242634 ··········</ocil:actions>
242647 ········</ocil:questionnaire>242635 ········</ocil:questionnaire>
242648 ········<ocil:questionnaire·id="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1">242636 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_home_directories_ocil:questionnaire:1">
242649 ··········<ocil:title>Ensure·SMAP·is·not·disabled·during·boot</ocil:title>242637 ··········<ocil:title>All·Interactive·User·Home·Directories·Must·Have·mode·0750·Or·Less·Permissive</ocil:title>
242650 ··········<ocil:actions>242638 ··········<ocil:actions>
242651 ············<ocil:test_action_ref>ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1</ocil:test_action_ref>242639 ············<ocil:test_action_ref>ocil:ssg-file_permissions_home_directories_action:testaction:1</ocil:test_action_ref>
242652 ··········</ocil:actions>242640 ··········</ocil:actions>
242653 ········</ocil:questionnaire>242641 ········</ocil:questionnaire>
242654 ········<ocil:questionnaire·id="ocil:ssg-partition_for_usr_ocil:questionnaire:1"> 
242655 ··········<ocil:title>Ensure·/usr·Located·On·Separate·Partition</ocil:title>242642 ········<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">
 242643 ··········<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>
242656 ··········<ocil:actions>242644 ··········<ocil:actions>
242657 ············<ocil:test_action_ref>ocil:ssg-partition_for_usr_action:testaction:1</ocil:test_action_ref>242645 ············<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>
242658 ··········</ocil:actions>242646 ··········</ocil:actions>
242659 ········</ocil:questionnaire>242647 ········</ocil:questionnaire>
242660 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1">242648 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chmod_ocil:questionnaire:1">
242661 ··········<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title>242649 ··········<ocil:title>Record·Any·Attempts·to·Run·chmod</ocil:title>
242662 ··········<ocil:actions>242650 ··········<ocil:actions>
242663 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>242651 ············<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chmod_action:testaction:1</ocil:test_action_ref>
242664 ··········</ocil:actions>242652 ··········</ocil:actions>
242665 ········</ocil:questionnaire>242653 ········</ocil:questionnaire>
242666 ········<ocil:questionnaire·id="ocil:ssg-cracklib_accounts_password_pam_difok_ocil:questionnaire:1">242654 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
242667 ··········<ocil:title>Set·Password·Strength·Minimum·Different·Characters</ocil:title>242655 ··········<ocil:title>Disable·X11·Forwarding</ocil:title>
242668 ··········<ocil:actions>242656 ··········<ocil:actions>
242669 ············<ocil:test_action_ref>ocil:ssg-cracklib_accounts_password_pam_difok_action:testaction:1</ocil:test_action_ref>242657 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
242670 ··········</ocil:actions>242658 ··········</ocil:actions>
242671 ········</ocil:questionnaire>242659 ········</ocil:questionnaire>
242672 ········<ocil:questionnaire·id="ocil:ssg-mount_option_noexec_remote_filesystems_ocil:questionnaire:1"> 
242673 ··········<ocil:title>Mount·Remote·Filesystems·with·noexec</ocil:title>242660 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">
 242661 ··········<ocil:title>Verify·Owner·on·cron.weekly</ocil:title>
242674 ··········<ocil:actions>242662 ··········<ocil:actions>
242675 ············<ocil:test_action_ref>ocil:ssg-mount_option_noexec_remote_filesystems_action:testaction:1</ocil:test_action_ref>242663 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1962197/1973910 bytes (99.41%) of diff not shown.
1.8 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ocil.xml
1.8 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ocil.xml
Ordering differences only
    
Offset 3, 8956 lines modifiedOffset 3, 8956 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1"> 
11 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-no_files_unowned_by_user_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-service_snmpd_disabled_ocil:questionnaire:1">
 11 ······<ocil:title>Disable·snmpd·Service</ocil:title>
17 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·User</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-no_files_unowned_by_user_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"> 
23 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title> 
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-service_snmpd_disabled_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_rm_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">
29 ······<ocil:title>Record·Any·Attempts·to·Run·rm</ocil:title>17 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_rm_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_filter_ocil:questionnaire:1"> 
35 ······<ocil:title>Enable·use·of·Berkeley·Packet·Filter·with·seccomp</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">
 23 ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_filter_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_permission_user_init_files_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_sgid_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·All·User·Initialization·Files·Have·Mode·0740·Or·Less·Permissive</ocil:title>29 ······<ocil:title>Ensure·All·SGID·Executables·Are·Authorized</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_permission_user_init_files_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_sgid_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1"> 
47 ······<ocil:title>Ensure·SMAP·is·not·disabled·during·boot</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_home_directories_ocil:questionnaire:1">
 35 ······<ocil:title>All·Interactive·User·Home·Directories·Must·Have·mode·0750·Or·Less·Permissive</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_home_directories_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-partition_for_usr_ocil:questionnaire:1"> 
53 ······<ocil:title>Ensure·/usr·Located·On·Separate·Partition</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">
 41 ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-partition_for_usr_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chmod_ocil:questionnaire:1">
59 ······<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title>47 ······<ocil:title>Record·Any·Attempts·to·Run·chmod</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chmod_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-cracklib_accounts_password_pam_difok_ocil:questionnaire:1"> 
65 ······<ocil:title>Set·Password·Strength·Minimum·Different·Characters</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
 53 ······<ocil:title>Disable·X11·Forwarding</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-cracklib_accounts_password_pam_difok_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-mount_option_noexec_remote_filesystems_ocil:questionnaire:1"> 
71 ······<ocil:title>Mount·Remote·Filesystems·with·noexec</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">
 59 ······<ocil:title>Verify·Owner·on·cron.weekly</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-mount_option_noexec_remote_filesystems_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_issue_net_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1">
77 ······<ocil:title>Verify·Group·Ownership·of·System·Login·Banner·for·Remote·Connections</ocil:title>65 ······<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_net_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_etc_selinux_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Permissions·On·/etc/selinux·Directory</ocil:title>71 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_etc_selinux_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_motd_ocil:questionnaire:1">
89 ······<ocil:title>Set·Password·Warning·Age</ocil:title>77 ······<ocil:title>Modify·the·System·Message·of·the·Day·Banner</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-banner_etc_motd_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-configure_user_data_backups_ocil:questionnaire:1"> 
95 ······<ocil:title>Configure·Backups·of·User·Data</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-package_dhcp_client_removed_ocil:questionnaire:1">
 83 ······<ocil:title>Uninstall·DHCP·Client·Package</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-configure_user_data_backups_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-package_dhcp_client_removed_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">
101 ······<ocil:title>Deactivate·Wireless·Network·Interfaces</ocil:title>89 ······<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-package_nftables_installed_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-service_xinetd_disabled_ocil:questionnaire:1">
107 ······<ocil:title>Install·nftables·Package</ocil:title>95 ······<ocil:title>Disable·xinetd·Service</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-package_nftables_installed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-service_xinetd_disabled_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_finit_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading·-·finit_module</ocil:title>101 ······<ocil:title>Verify·Owner·on·cron.monthly</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_finit_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-logind_session_timeout_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_weekly_ocil:questionnaire:1">
119 ······<ocil:title>Configure·Logind·to·terminate·idle·sessions·after·certain·time·of·inactivity</ocil:title>107 ······<ocil:title>Verify·Group·Who·Owns·cron.weekly</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-logind_session_timeout_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_weekly_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>110 ······</ocil:actions>
Max diff block lines reached; 1876702/1888518 bytes (99.37%) of diff not shown.
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ds.xml
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ds.xml
    
Offset 21, 15 lines modifiedOffset 21, 15 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.micro.5-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.micro.5-patch.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.micro.5-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.micro.5-patch.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.3">30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.3">
31 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.3</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.3</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.4">34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.4">
35 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.4</cpe-dict:title>35 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.4</cpe-dict:title>
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 ······</cpe-dict:cpe-item>41 ······</cpe-dict:cpe-item>
42 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-microos:5.2">42 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-microos:5.2">
43 ········<cpe-dict:title·xml:lang="en-us">SLE·MicroOS·5.2</cpe-dict:title>43 ········<cpe-dict:title·xml:lang="en-us">SLE·MicroOS·5.2</cpe-dict:title>
44 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>44 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>
45 ······</cpe-dict:cpe-item>45 ······</cpe-dict:cpe-item>
46 ····</cpe-dict:cpe-list>46 ····</cpe-dict:cpe-list>
47 ··</ds:component>47 ··</ds:component>
48 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-xccdf.xml"·timestamp="2025-02-28T20:08:00">48 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-xccdf.xml"·timestamp="2025-03-01T22:08:00">
49 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLMICRO5"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">49 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLMICRO5"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
50 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>50 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
51 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·Micro·5</xccdf-1.2:title>51 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·Micro·5</xccdf-1.2:title>
52 ······<xccdf-1.2:description>52 ······<xccdf-1.2:description>
53 ········This·guide·presents·a·catalog·of·security-relevant53 ········This·guide·presents·a·catalog·of·security-relevant
54 configuration·settings·for·SUSE·Linux·Enterprise·Micro·5.·It·is·a·rendering·of54 configuration·settings·for·SUSE·Linux·Enterprise·Micro·5.·It·is·a·rendering·of
55 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)55 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 124816, 15 lines modifiedOffset 124816, 15 lines modified
124816 ··············<xccdf-1.2:check-content-ref·href="ssg-slmicro5-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_percentage_ocil:questionnaire:1"/>124816 ··············<xccdf-1.2:check-content-ref·href="ssg-slmicro5-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_percentage_ocil:questionnaire:1"/>
124817 ············</xccdf-1.2:check>124817 ············</xccdf-1.2:check>
124818 ··········</xccdf-1.2:Rule>124818 ··········</xccdf-1.2:Rule>
124819 ········</xccdf-1.2:Group>124819 ········</xccdf-1.2:Group>
124820 ······</xccdf-1.2:Group>124820 ······</xccdf-1.2:Group>
124821 ····</xccdf-1.2:Benchmark>124821 ····</xccdf-1.2:Benchmark>
124822 ··</ds:component>124822 ··</ds:component>
124823 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-oval.xml"·timestamp="2025-02-28T20:08:00">124823 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-oval.xml"·timestamp="2025-03-01T22:08:00">
124824 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">124824 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
124825 ······<oval-def:generator>124825 ······<oval-def:generator>
124826 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>124826 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
124827 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>124827 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
124828 ········<oval:schema_version>5.11</oval:schema_version>124828 ········<oval:schema_version>5.11</oval:schema_version>
124829 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>124829 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
124830 ······</oval-def:generator>124830 ······</oval-def:generator>
Offset 146446, 6700 lines modifiedOffset 146446, 6740 lines modified
146446 ············</oval-def:arithmetic>146446 ············</oval-def:arithmetic>
146447 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>146447 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
146448 ··········</oval-def:arithmetic>146448 ··········</oval-def:arithmetic>
146449 ········</oval-def:local_variable>146449 ········</oval-def:local_variable>
146450 ······</oval-def:variables>146450 ······</oval-def:variables>
146451 ····</oval-def:oval_definitions>146451 ····</oval-def:oval_definitions>
146452 ··</ds:component>146452 ··</ds:component>
146453 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"·timestamp="2025-02-28T20:08:00">146453 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"·timestamp="2025-03-01T22:08:00">
146454 ····<ocil:ocil>146454 ····<ocil:ocil>
146455 ······<ocil:generator>146455 ······<ocil:generator>
146456 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>146456 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
146457 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>146457 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
146458 ········<ocil:schema_version>2.0</ocil:schema_version>146458 ········<ocil:schema_version>2.0</ocil:schema_version>
146459 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>146459 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
146460 ······</ocil:generator>146460 ······</ocil:generator>
146461 ······<ocil:questionnaires>146461 ······<ocil:questionnaires>
146462 ········<ocil:questionnaire·id="ocil:ssg-set_firewalld_appropriate_zone_ocil:questionnaire:1"> 
146463 ··········<ocil:title>Ensure·network·interfaces·are·assigned·to·appropriate·zone</ocil:title> 
146464 ··········<ocil:actions> 
146465 ············<ocil:test_action_ref>ocil:ssg-set_firewalld_appropriate_zone_action:testaction:1</ocil:test_action_ref> 
146466 ··········</ocil:actions> 
146467 ········</ocil:questionnaire> 
146468 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_gpasswd_ocil:questionnaire:1">146462 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_percentage_ocil:questionnaire:1">
146469 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·gpasswd</ocil:title>146463 ··········<ocil:title>Configure·auditd·space_left·on·Low·Disk·Space</ocil:title>
146470 ··········<ocil:actions>146464 ··········<ocil:actions>
146471 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_gpasswd_action:testaction:1</ocil:test_action_ref>146465 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_percentage_action:testaction:1</ocil:test_action_ref>
146472 ··········</ocil:actions>146466 ··········</ocil:actions>
146473 ········</ocil:questionnaire>146467 ········</ocil:questionnaire>
146474 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_group_ocil:questionnaire:1">146468 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_grub2_cfg_ocil:questionnaire:1">
146475 ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/group</ocil:title>146469 ··········<ocil:title>Verify·/boot/grub2/grub.cfg·Group·Ownership</ocil:title>
146476 ··········<ocil:actions>146470 ··········<ocil:actions>
146477 ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_group_action:testaction:1</ocil:test_action_ref>146471 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_grub2_cfg_action:testaction:1</ocil:test_action_ref>
146478 ··········</ocil:actions>146472 ··········</ocil:actions>
146479 ········</ocil:questionnaire>146473 ········</ocil:questionnaire>
146480 ········<ocil:questionnaire·id="ocil:ssg-no_shelllogin_for_systemaccounts_ocil:questionnaire:1"> 
146481 ··········<ocil:title>Ensure·that·System·Accounts·Do·Not·Run·a·Shell·Upon·Login</ocil:title>146474 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_grub2_cfg_ocil:questionnaire:1">
 146475 ··········<ocil:title>Verify·/boot/grub2/grub.cfg·Permissions</ocil:title>
146482 ··········<ocil:actions>146476 ··········<ocil:actions>
146483 ············<ocil:test_action_ref>ocil:ssg-no_shelllogin_for_systemaccounts_action:testaction:1</ocil:test_action_ref>146477 ············<ocil:test_action_ref>ocil:ssg-file_permissions_grub2_cfg_action:testaction:1</ocil:test_action_ref>
146484 ··········</ocil:actions>146478 ··········</ocil:actions>
146485 ········</ocil:questionnaire>146479 ········</ocil:questionnaire>
146486 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_rm_ocil:questionnaire:1">146480 ········<ocil:questionnaire·id="ocil:ssg-mount_option_home_nodev_ocil:questionnaire:1">
146487 ··········<ocil:title>Record·Any·Attempts·to·Run·rm</ocil:title>146481 ··········<ocil:title>Add·nodev·Option·to·/home</ocil:title>
146488 ··········<ocil:actions>146482 ··········<ocil:actions>
146489 ············<ocil:test_action_ref>ocil:ssg-audit_rules_execution_rm_action:testaction:1</ocil:test_action_ref>146483 ············<ocil:test_action_ref>ocil:ssg-mount_option_home_nodev_action:testaction:1</ocil:test_action_ref>
146490 ··········</ocil:actions>146484 ··········</ocil:actions>
146491 ········</ocil:questionnaire>146485 ········</ocil:questionnaire>
146492 ········<ocil:questionnaire·id="ocil:ssg-group_unique_id_ocil:questionnaire:1">146486 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_ocil:questionnaire:1">
146493 ··········<ocil:title>Ensure·All·Groups·on·the·System·Have·Unique·Group·ID</ocil:title>146487 ··········<ocil:title>Limit·Password·Reuse</ocil:title>
146494 ··········<ocil:actions>146488 ··········<ocil:actions>
146495 ············<ocil:test_action_ref>ocil:ssg-group_unique_id_action:testaction:1</ocil:test_action_ref>146489 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_action:testaction:1</ocil:test_action_ref>
146496 ··········</ocil:actions>146490 ··········</ocil:actions>
146497 ········</ocil:questionnaire>146491 ········</ocil:questionnaire>
146498 ········<ocil:questionnaire·id="ocil:ssg-package_audit-audispd-plugins_installed_ocil:questionnaire:1">146492 ········<ocil:questionnaire·id="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1">
146499 ··········<ocil:title>Ensure·the·default·plugins·for·the·audit·dispatcher·are·Installed</ocil:title>146493 ··········<ocil:title>Verify·firewalld·Enabled</ocil:title>
146500 ··········<ocil:actions>146494 ··········<ocil:actions>
146501 ············<ocil:test_action_ref>ocil:ssg-package_audit-audispd-plugins_installed_action:testaction:1</ocil:test_action_ref>146495 ············<ocil:test_action_ref>ocil:ssg-service_firewalld_enabled_action:testaction:1</ocil:test_action_ref>
146502 ··········</ocil:actions>146496 ··········</ocil:actions>
146503 ········</ocil:questionnaire>146497 ········</ocil:questionnaire>
146504 ········<ocil:questionnaire·id="ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_ocil:questionnaire:1"> 
146505 ··········<ocil:title>The·operating·system·must·restrict·privilege·elevation·to·authorized·personnel</ocil:title>146498 ········<ocil:questionnaire·id="ocil:ssg-set_nftables_base_chain_ocil:questionnaire:1">
 146499 ··········<ocil:title>Ensure·Base·Chains·Exist·for·Nftables</ocil:title>
146506 ··········<ocil:actions>146500 ··········<ocil:actions>
146507 ············<ocil:test_action_ref>ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_action:testaction:1</ocil:test_action_ref>146501 ············<ocil:test_action_ref>ocil:ssg-set_nftables_base_chain_action:testaction:1</ocil:test_action_ref>
146508 ··········</ocil:actions>146502 ··········</ocil:actions>
146509 ········</ocil:questionnaire>146503 ········</ocil:questionnaire>
146510 ········<ocil:questionnaire·id="ocil:ssg-accounts_authorized_local_users_ocil:questionnaire:1"> 
146511 ··········<ocil:title>Only·Authorized·Local·User·Accounts·Exist·on·Operating·System</ocil:title>146504 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">
 146505 ··········<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>
146512 ··········<ocil:actions>146506 ··········<ocil:actions>
146513 ············<ocil:test_action_ref>ocil:ssg-accounts_authorized_local_users_action:testaction:1</ocil:test_action_ref>146507 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
146514 ··········</ocil:actions>146508 ··········</ocil:actions>
146515 ········</ocil:questionnaire>146509 ········</ocil:questionnaire>
146516 ········<ocil:questionnaire·id="ocil:ssg-timer_logrotate_enabled_ocil:questionnaire:1">146510 ········<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_no_world_writable_programs_ocil:questionnaire:1">
146517 ··········<ocil:title>Enable·logrotate·Timer</ocil:title>146511 ··········<ocil:title>User·Initialization·Files·Must·Not·Run·World-Writable·Programs</ocil:title>
146518 ··········<ocil:actions>146512 ··········<ocil:actions>
146519 ············<ocil:test_action_ref>ocil:ssg-timer_logrotate_enabled_action:testaction:1</ocil:test_action_ref>146513 ············<ocil:test_action_ref>ocil:ssg-accounts_user_dot_no_world_writable_programs_action:testaction:1</ocil:test_action_ref>
146520 ··········</ocil:actions>146514 ··········</ocil:actions>
146521 ········</ocil:questionnaire>146515 ········</ocil:questionnaire>
Max diff block lines reached; 1044276/1056312 bytes (98.86%) of diff not shown.
985 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ocil.xml
985 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ocil.xml
Ordering differences only
    
Offset 3, 6691 lines modifiedOffset 3, 6731 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
 10 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_percentage_ocil:questionnaire:1">
 11 ······<ocil:title>Configure·auditd·space_left·on·Low·Disk·Space</ocil:title>
10 ····<ocil:questionnaire·id="ocil:ssg-set_firewalld_appropriate_zone_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·network·interfaces·are·assigned·to·appropriate·zone</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-set_firewalld_appropriate_zone_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_gpasswd_ocil:questionnaire:1"> 
17 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·gpasswd</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_gpasswd_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_percentage_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_group_ocil:questionnaire:1"> 
23 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/group</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_grub2_cfg_ocil:questionnaire:1">
 17 ······<ocil:title>Verify·/boot/grub2/grub.cfg·Group·Ownership</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_group_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_grub2_cfg_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-no_shelllogin_for_systemaccounts_ocil:questionnaire:1"> 
29 ······<ocil:title>Ensure·that·System·Accounts·Do·Not·Run·a·Shell·Upon·Login</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_grub2_cfg_ocil:questionnaire:1">
 23 ······<ocil:title>Verify·/boot/grub2/grub.cfg·Permissions</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-no_shelllogin_for_systemaccounts_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_grub2_cfg_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_rm_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nodev_ocil:questionnaire:1">
35 ······<ocil:title>Record·Any·Attempts·to·Run·rm</ocil:title>29 ······<ocil:title>Add·nodev·Option·to·/home</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_rm_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nodev_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-group_unique_id_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·All·Groups·on·the·System·Have·Unique·Group·ID</ocil:title>35 ······<ocil:title>Limit·Password·Reuse</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-group_unique_id_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-package_audit-audispd-plugins_installed_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·the·default·plugins·for·the·audit·dispatcher·are·Installed</ocil:title>41 ······<ocil:title>Verify·firewalld·Enabled</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-package_audit-audispd-plugins_installed_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-service_firewalld_enabled_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_ocil:questionnaire:1"> 
53 ······<ocil:title>The·operating·system·must·restrict·privilege·elevation·to·authorized·personnel</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-set_nftables_base_chain_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·Base·Chains·Exist·for·Nftables</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-set_nftables_base_chain_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-accounts_authorized_local_users_ocil:questionnaire:1"> 
59 ······<ocil:title>Only·Authorized·Local·User·Accounts·Exist·on·Operating·System</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">
 53 ······<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-accounts_authorized_local_users_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-timer_logrotate_enabled_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_no_world_writable_programs_ocil:questionnaire:1">
65 ······<ocil:title>Enable·logrotate·Timer</ocil:title>59 ······<ocil:title>User·Initialization·Files·Must·Not·Run·World-Writable·Programs</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-timer_logrotate_enabled_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-accounts_user_dot_no_world_writable_programs_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-package_pam_apparmor_installed_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_shadow_ocil:questionnaire:1">
71 ······<ocil:title>Install·the·pam_apparmor·Package</ocil:title>65 ······<ocil:title>Verify·Group·Who·Owns·shadow·File</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-package_pam_apparmor_installed_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_shadow_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1">
77 ······<ocil:title>Record·Any·Attempts·to·Run·chcon</ocil:title>71 ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_issue_ocil:questionnaire:1"> 
83 ······<ocil:title>Verify·Group·Ownership·of·System·Login·Banner</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-package_policycoreutils_installed_ocil:questionnaire:1">
 77 ······<ocil:title>Install·policycoreutils·Package</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-package_policycoreutils_installed_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1"> 
89 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·openat</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-ensure_GPG_keys_are_configured_ocil:questionnaire:1">
 83 ······<ocil:title>Ensure·GPG·keys·are·configured</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-ensure_GPG_keys_are_configured_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">
95 ······<ocil:title>Verify·User·Who·Owns·Backup·passwd·File</ocil:title>89 ······<ocil:title>The·Chrony·package·is·installed</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-accounts_users_home_files_permissions_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">
101 ······<ocil:title>All·User·Files·and·Directories·In·The·Home·Directory·Must·Have·Mode·0750·Or·Less·Permissive</ocil:title>95 ······<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-accounts_users_home_files_permissions_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sudo_require_reauthentication_ocil:questionnaire:1"> 
107 ······<ocil:title>Require·Re-Authentication·When·Using·the·sudo·Command</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_ciphers_ordered_stig_ocil:questionnaire:1">
 101 ······<ocil:title>Use·Only·FIPS·140-2·Validated·Ciphers</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sudo_require_reauthentication_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sshd_use_approved_ciphers_ordered_stig_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nodev_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_motd_ocil:questionnaire:1">
113 ······<ocil:title>Add·nodev·Option·to·/home</ocil:title>107 ······<ocil:title>Modify·the·System·Message·of·the·Day·Banner</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nodev_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-banner_etc_motd_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1"> 
119 ······<ocil:title>Verify·Permissions·on·/etc/at.allow·file</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fsetxattr_ocil:questionnaire:1">
 113 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fsetxattr</ocil:title>
Max diff block lines reached; 996676/1008640 bytes (98.81%) of diff not shown.