Offset 1, 6 lines modified | Offset 1, 6 lines modified | ||
1 | · | 1 | ·4177346ee1b6451d7c1613cf5f44a6b6·153740·admin·optional·ssg-applications_0.1.76-1_all.deb |
2 | ·ea0c1f19113a8a6c0a6e8b10e8e208a9·32632·admin·optional·ssg-base_0.1.76-1_all.deb | 2 | ·ea0c1f19113a8a6c0a6e8b10e8e208a9·32632·admin·optional·ssg-base_0.1.76-1_all.deb |
3 | ·bf7bac2809ae4741dfbfcfc0db40ab0a·3725628·admin·optional·ssg-debderived_0.1.76-1_all.deb | ||
4 | ·fcd3eb20c308d0a21bf0e3e00278c909·1232392·admin·optional·ssg-debian_0.1.76-1_all.deb | ||
5 | · | 3 | ·c88e8e42baee3fc6124affc29224cd85·3725852·admin·optional·ssg-debderived_0.1.76-1_all.deb |
4 | ·20f9dfa3980fc7b181f978e2989303ac·1232184·admin·optional·ssg-debian_0.1.76-1_all.deb | ||
5 | ·f73dffb0b8e85ebe6b507af289d02441·37100544·admin·optional·ssg-nondebian_0.1.76-1_all.deb |
Offset 1, 3 lines modified | Offset 1, 3 lines modified | ||
1 | -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary | 1 | -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary |
2 | -rw-r--r--···0········0········0·····1728·2025-03-01·08:08:00.000000·control.tar.xz | 2 | -rw-r--r--···0········0········0·····1728·2025-03-01·08:08:00.000000·control.tar.xz |
3 | -rw-r--r--···0········0········0···151 | 3 | -rw-r--r--···0········0········0···151820·2025-03-01·08:08:00.000000·data.tar.xz |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/a:google:chromium-browser"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/a:google:chromium-browser"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Chromium.·It·is·a·rendering·of | 40 | configuration·settings·for·Chromium.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 1675, 15 lines modified | Offset 1675, 15 lines modified | ||
1675 | ··········<xccdf-1.2:check·system="http://scap.nist.gov/schema/ocil/2"> | 1675 | ··········<xccdf-1.2:check·system="http://scap.nist.gov/schema/ocil/2"> |
1676 | ············<xccdf-1.2:check-content-ref·href="ssg-chromium-ocil.xml"·name="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"/> | 1676 | ············<xccdf-1.2:check-content-ref·href="ssg-chromium-ocil.xml"·name="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"/> |
1677 | ··········</xccdf-1.2:check> | 1677 | ··········</xccdf-1.2:check> |
1678 | ········</xccdf-1.2:Rule> | 1678 | ········</xccdf-1.2:Rule> |
1679 | ······</xccdf-1.2:Group> | 1679 | ······</xccdf-1.2:Group> |
1680 | ····</xccdf-1.2:Benchmark> | 1680 | ····</xccdf-1.2:Benchmark> |
1681 | ··</ds:component> | 1681 | ··</ds:component> |
1682 | ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-oval.xml"·timestamp="2025-0 | 1682 | ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-oval.xml"·timestamp="2025-03-01T22:08:00"> |
1683 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 1683 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
1684 | ······<oval-def:generator> | 1684 | ······<oval-def:generator> |
1685 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 1685 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
1686 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 1686 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
1687 | ········<oval:schema_version>5.11</oval:schema_version> | 1687 | ········<oval:schema_version>5.11</oval:schema_version> |
1688 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 1688 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
1689 | ······</oval-def:generator> | 1689 | ······</oval-def:generator> |
Offset 2539, 813 lines modified | Offset 2539, 813 lines modified | ||
2539 | ········<oval-def:external_variable·id="oval:ssg-var_enable_encrypted_searching:var:1"·version="1"·datatype="string"·comment="Expected·search·provider·name"/> | 2539 | ········<oval-def:external_variable·id="oval:ssg-var_enable_encrypted_searching:var:1"·version="1"·datatype="string"·comment="Expected·search·provider·name"/> |
2540 | ········<oval-def:external_variable·id="oval:ssg-var_extension_whitelist:var:1"·version="1"·datatype="string"·comment="Expected·approved·extensions"/> | 2540 | ········<oval-def:external_variable·id="oval:ssg-var_extension_whitelist:var:1"·version="1"·datatype="string"·comment="Expected·approved·extensions"/> |
2541 | ········<oval-def:external_variable·id="oval:ssg-var_auth_schema:var:1"·version="1"·datatype="string"·comment="Expected·HTTP·authentication·type"/> | 2541 | ········<oval-def:external_variable·id="oval:ssg-var_auth_schema:var:1"·version="1"·datatype="string"·comment="Expected·HTTP·authentication·type"/> |
2542 | ········<oval-def:external_variable·id="oval:ssg-var_trusted_home_page:var:1"·version="1"·datatype="string"·comment="Expected·home·page"/> | 2542 | ········<oval-def:external_variable·id="oval:ssg-var_trusted_home_page:var:1"·version="1"·datatype="string"·comment="Expected·home·page"/> |
2543 | ······</oval-def:variables> | 2543 | ······</oval-def:variables> |
2544 | ····</oval-def:oval_definitions> | 2544 | ····</oval-def:oval_definitions> |
2545 | ··</ds:component> | 2545 | ··</ds:component> |
2546 | ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-ocil.xml"·timestamp="2025-0 | 2546 | ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
2547 | ····<ocil:ocil> | 2547 | ····<ocil:ocil> |
2548 | ······<ocil:generator> | 2548 | ······<ocil:generator> |
2549 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 2549 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
2550 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 2550 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
2551 | ········<ocil:schema_version>2.0</ocil:schema_version> | 2551 | ········<ocil:schema_version>2.0</ocil:schema_version> |
2552 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 2552 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
2553 | ······</ocil:generator> | 2553 | ······</ocil:generator> |
2554 | ······<ocil:questionnaires> | 2554 | ······<ocil:questionnaires> |
2555 | ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1"> | ||
2556 | ··········<ocil:title>Enable·Only·Approved·Plugins</ocil:title> | ||
2557 | ··········<ocil:actions> | ||
2558 | ············<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref> | ||
2559 | ··········</ocil:actions> | ||
2560 | ········</ocil:questionnaire> | ||
2561 | ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_ | 2555 | ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_popups_ocil:questionnaire:1"> |
2562 | ··········<ocil:title>Disable· | 2556 | ··········<ocil:title>Disable·Popups</ocil:title> |
2563 | ··········<ocil:actions> | 2557 | ··········<ocil:actions> |
2564 | ············<ocil:test_action_ref>ocil:ssg-chromium_disable_ | 2558 | ············<ocil:test_action_ref>ocil:ssg-chromium_disable_popups_action:testaction:1</ocil:test_action_ref> |
2565 | ··········</ocil:actions> | 2559 | ··········</ocil:actions> |
2566 | ········</ocil:questionnaire> | 2560 | ········</ocil:questionnaire> |
2567 | ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_ | 2561 | ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_incognito_mode_ocil:questionnaire:1"> |
2568 | ··········<ocil:title>Disable· | 2562 | ··········<ocil:title>Disable·Incognito·Mode</ocil:title> |
2569 | ··········<ocil:actions> | 2563 | ··········<ocil:actions> |
2570 | ············<ocil:test_action_ref>ocil:ssg-chromium_disable_ | 2564 | ············<ocil:test_action_ref>ocil:ssg-chromium_disable_incognito_mode_action:testaction:1</ocil:test_action_ref> |
2571 | ··········</ocil:actions> | 2565 | ··········</ocil:actions> |
2572 | ········</ocil:questionnaire> | 2566 | ········</ocil:questionnaire> |
2573 | ········<ocil:questionnaire·id="ocil:ssg-chromium_disa | 2567 | ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1"> |
2574 | ··········<ocil:title>Disable· | 2568 | ··········<ocil:title>Disable·Metrics·Reporting</ocil:title> |
2575 | ··········<ocil:actions> | 2569 | ··········<ocil:actions> |
2576 | ············<ocil:test_action_ref>ocil:ssg-chromium_disa | 2570 | ············<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref> |
2577 | ··········</ocil:actions> | 2571 | ··········</ocil:actions> |
2578 | ········</ocil:questionnaire> | 2572 | ········</ocil:questionnaire> |
2579 | ········<ocil:questionnaire·id="ocil:ssg-chromium_ | 2573 | ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_encrypted_searching_ocil:questionnaire:1"> |
2580 | ··········<ocil:title> | 2574 | ··········<ocil:title>Enable·Encrypted·Searching</ocil:title> |
2581 | ··········<ocil:actions> | 2575 | ··········<ocil:actions> |
2582 | ············<ocil:test_action_ref>ocil:ssg-chromium_ | 2576 | ············<ocil:test_action_ref>ocil:ssg-chromium_enable_encrypted_searching_action:testaction:1</ocil:test_action_ref> |
2583 | ··········</ocil:actions> | 2577 | ··········</ocil:actions> |
2584 | ········</ocil:questionnaire> | 2578 | ········</ocil:questionnaire> |
2585 | ········<ocil:questionnaire·id="ocil:ssg-chromium_ | 2579 | ········<ocil:questionnaire·id="ocil:ssg-chromium_blacklist_extension_installation_ocil:questionnaire:1"> |
2586 | ··········<ocil:title>Disable·A | 2580 | ··········<ocil:title>Disable·All·Extensions·by·Default</ocil:title> |
2587 | ··········<ocil:actions> | 2581 | ··········<ocil:actions> |
2588 | ············<ocil:test_action_ref>ocil:ssg-chromium_ | 2582 | ············<ocil:test_action_ref>ocil:ssg-chromium_blacklist_extension_installation_action:testaction:1</ocil:test_action_ref> |
2589 | ··········</ocil:actions> | 2583 | ··········</ocil:actions> |
2590 | ········</ocil:questionnaire> | 2584 | ········</ocil:questionnaire> |
2591 | ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1"> | 2585 | ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1"> |
2592 | ··········<ocil:title>Enable·Saving·the·Browser·History</ocil:title> | 2586 | ··········<ocil:title>Enable·Saving·the·Browser·History</ocil:title> |
2593 | ··········<ocil:actions> | 2587 | ··········<ocil:actions> |
2594 | ············<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref> | 2588 | ············<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref> |
2595 | ··········</ocil:actions> | 2589 | ··········</ocil:actions> |
2596 | ········</ocil:questionnaire> | 2590 | ········</ocil:questionnaire> |
2597 | ········<ocil:questionnaire·id="ocil:ssg-chromium_ | 2591 | ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1"> |
2598 | ··········<ocil:title> | 2592 | ··········<ocil:title>Enable·Only·Approved·Plugins</ocil:title> |
2599 | ··········<ocil:actions> | 2593 | ··········<ocil:actions> |
2600 | ············<ocil:test_action_ref>ocil:ssg-chromium_ | 2594 | ············<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref> |
2601 | ··········</ocil:actions> | 2595 | ··········</ocil:actions> |
2602 | ········</ocil:questionnaire> | 2596 | ········</ocil:questionnaire> |
2603 | ········<ocil:questionnaire·id="ocil:ssg-chromium_d | 2597 | ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_google_sync_ocil:questionnaire:1"> |
2604 | ··········<ocil:title> | 2598 | ··········<ocil:title>Disable·Data·Synchronization·to·Google</ocil:title> |
2605 | ··········<ocil:actions> | 2599 | ··········<ocil:actions> |
2606 | ············<ocil:test_action_ref>ocil:ssg-chromium_d | 2600 | ············<ocil:test_action_ref>ocil:ssg-chromium_disable_google_sync_action:testaction:1</ocil:test_action_ref> |
2607 | ··········</ocil:actions> | 2601 | ··········</ocil:actions> |
2608 | ········</ocil:questionnaire> | 2602 | ········</ocil:questionnaire> |
2609 | ········<ocil:questionnaire·id="ocil:ssg-chromium_ | 2603 | ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1"> |
2610 | ··········<ocil:title> | 2604 | ··········<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title> |
2611 | ··········<ocil:actions> | 2605 | ··········<ocil:actions> |
2612 | ············<ocil:test_action_ref>ocil:ssg-chromium_ | 2606 | ············<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref> |
2613 | ··········</ocil:actions> | 2607 | ··········</ocil:actions> |
2614 | ········</ocil:questionnaire> | 2608 | ········</ocil:questionnaire> |
2615 | ········<ocil:questionnaire·id="ocil:ssg-chromium_ | 2609 | ········<ocil:questionnaire·id="ocil:ssg-chromium_extension_whitelist_ocil:questionnaire:1"> |
2616 | ··········<ocil:title> | 2610 | ··········<ocil:title>Enable·Only·Approved·Extensions</ocil:title> |
2617 | ··········<ocil:actions> | 2611 | ··········<ocil:actions> |
2618 | ············<ocil:test_action_ref>ocil:ssg-chromium_ | 2612 | ············<ocil:test_action_ref>ocil:ssg-chromium_extension_whitelist_action:testaction:1</ocil:test_action_ref> |
2619 | ··········</ocil:actions> | 2613 | ··········</ocil:actions> |
2620 | ········</ocil:questionnaire> | 2614 | ········</ocil:questionnaire> |
2621 | ········<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"> | 2615 | ········<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"> |
2622 | ··········<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title> | 2616 | ··········<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title> |
2623 | ··········<ocil:actions> | 2617 | ··········<ocil:actions> |
2624 | ············<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref> | 2618 | ············<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref> |
2625 | ··········</ocil:actions> | 2619 | ··········</ocil:actions> |
Max diff block lines reached; 68785/80560 bytes (85.38%) of diff not shown. |
Offset 3, 795 lines modified | Offset 3, 795 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1"> | ||
11 | ······<ocil:title>Enable·Only·Approved·Plugins</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_ | 10 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_popups_ocil:questionnaire:1"> |
17 | ······<ocil:title>Disable· | 11 | ······<ocil:title>Disable·Popups</ocil:title> |
18 | ······<ocil:actions> | 12 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg-chromium_disable_ | 13 | ········<ocil:test_action_ref>ocil:ssg-chromium_disable_popups_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 14 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_ | 16 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_incognito_mode_ocil:questionnaire:1"> |
23 | ······<ocil:title>Disable· | 17 | ······<ocil:title>Disable·Incognito·Mode</ocil:title> |
24 | ······<ocil:actions> | 18 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg-chromium_disable_ | 19 | ········<ocil:test_action_ref>ocil:ssg-chromium_disable_incognito_mode_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 20 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disa | 22 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1"> |
29 | ······<ocil:title>Disable· | 23 | ······<ocil:title>Disable·Metrics·Reporting</ocil:title> |
30 | ······<ocil:actions> | 24 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg-chromium_disa | 25 | ········<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 26 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-chromium_ | 28 | ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_encrypted_searching_ocil:questionnaire:1"> |
35 | ······<ocil:title> | 29 | ······<ocil:title>Enable·Encrypted·Searching</ocil:title> |
36 | ······<ocil:actions> | 30 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg-chromium_ | 31 | ········<ocil:test_action_ref>ocil:ssg-chromium_enable_encrypted_searching_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 32 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-chromium_ | 34 | ····<ocil:questionnaire·id="ocil:ssg-chromium_blacklist_extension_installation_ocil:questionnaire:1"> |
41 | ······<ocil:title>Disable·A | 35 | ······<ocil:title>Disable·All·Extensions·by·Default</ocil:title> |
42 | ······<ocil:actions> | 36 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg-chromium_ | 37 | ········<ocil:test_action_ref>ocil:ssg-chromium_blacklist_extension_installation_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 38 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1"> | 40 | ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1"> |
47 | ······<ocil:title>Enable·Saving·the·Browser·History</ocil:title> | 41 | ······<ocil:title>Enable·Saving·the·Browser·History</ocil:title> |
48 | ······<ocil:actions> | 42 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref> | 43 | ········<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 44 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-chromium_ | 46 | ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 47 | ······<ocil:title>Enable·Only·Approved·Plugins</ocil:title> |
54 | ······<ocil:actions> | 48 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg-chromium_ | 49 | ········<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 50 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-chromium_d | 52 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_google_sync_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 53 | ······<ocil:title>Disable·Data·Synchronization·to·Google</ocil:title> |
60 | ······<ocil:actions> | 54 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg-chromium_d | 55 | ········<ocil:test_action_ref>ocil:ssg-chromium_disable_google_sync_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 56 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-chromium_ | 58 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1"> |
65 | ······<ocil:title> | 59 | ······<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title> |
66 | ······<ocil:actions> | 60 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg-chromium_ | 61 | ········<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 62 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg-chromium_ | 64 | ····<ocil:questionnaire·id="ocil:ssg-chromium_extension_whitelist_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 65 | ······<ocil:title>Enable·Only·Approved·Extensions</ocil:title> |
72 | ······<ocil:actions> | 66 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg-chromium_ | 67 | ········<ocil:test_action_ref>ocil:ssg-chromium_extension_whitelist_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 68 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"> | 70 | ····<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"> |
77 | ······<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title> | 71 | ······<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title> |
78 | ······<ocil:actions> | 72 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref> | 73 | ········<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 74 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_ | 76 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1"> |
83 | ······<ocil:title>Disable· | 77 | ······<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title> |
84 | ······<ocil:actions> | 78 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg-chromium_disable_ | 79 | ········<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 80 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_ | 82 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_thirdparty_cookies_ocil:questionnaire:1"> |
89 | ······<ocil:title>Disable· | 83 | ······<ocil:title>Disable·3rd·Party·Cookies</ocil:title> |
90 | ······<ocil:actions> | 84 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg-chromium_disable_ | 85 | ········<ocil:test_action_ref>ocil:ssg-chromium_disable_thirdparty_cookies_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 86 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-chromium_ | 88 | ····<ocil:questionnaire·id="ocil:ssg-chromium_check_cert_revocation_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 89 | ······<ocil:title>Enable·Online·OCSP/CRL·Certificate·Checks</ocil:title> |
96 | ······<ocil:actions> | 90 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg-chromium_ | 91 | ········<ocil:test_action_ref>ocil:ssg-chromium_check_cert_revocation_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 92 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-chromium_ | 94 | ····<ocil:questionnaire·id="ocil:ssg-chromium_policy_file_ocil:questionnaire:1"> |
101 | ······<ocil:title> | 95 | ······<ocil:title>Ensure·the·Chromium·Policy·Configuration·File·Exists</ocil:title> |
102 | ······<ocil:actions> | 96 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg-chromium_ | 97 | ········<ocil:test_action_ref>ocil:ssg-chromium_policy_file_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 98 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_ | 100 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cleartext_passwords_ocil:questionnaire:1"> |
107 | ······<ocil:title>Disable· | 101 | ······<ocil:title>Disable·Use·of·Cleartext·Passwords</ocil:title> |
108 | ······<ocil:actions> | 102 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg-chromium_disable_ | 103 | ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cleartext_passwords_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 104 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-chromium_ | 106 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_network_prediction_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 107 | ······<ocil:title>Disable·Network·Prediction</ocil:title> |
114 | ······<ocil:actions> | 108 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg-chromium_ | 109 | ········<ocil:test_action_ref>ocil:ssg-chromium_disable_network_prediction_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 110 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-chromium_ | 112 | ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_session_cookies_ocil:questionnaire:1"> |
119 | ······<ocil:title> | 113 | ······<ocil:title>Disable·Session·Cookies</ocil:title> |
120 | ······<ocil:actions> | 114 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg-chromium_ | 115 | ········<ocil:test_action_ref>ocil:ssg-chromium_disable_session_cookies_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 116 | ······</ocil:actions> |
123 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
124 | ····<ocil:questionnaire·id="ocil:ssg-chromium_ | 118 | ····<ocil:questionnaire·id="ocil:ssg-chromium_http_authentication_ocil:questionnaire:1"> |
125 | ······<ocil:title> | 119 | ······<ocil:title>Set·Chromium's·HTTP·Authentication·Scheme</ocil:title> |
126 | ······<ocil:actions> | 120 | ······<ocil:actions> |
127 | ········<ocil:test_action_ref>ocil:ssg-chromium_ | 121 | ········<ocil:test_action_ref>ocil:ssg-chromium_http_authentication_action:testaction:1</ocil:test_action_ref> |
128 | ······</ocil:actions> | 122 | ······</ocil:actions> |
129 | ····</ocil:questionnaire> | 123 | ····</ocil:questionnaire> |
Max diff block lines reached; 59378/71723 bytes (82.79%) of diff not shown. |
Offset 19, 15 lines modified | Offset 19, 15 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service:1"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service:1"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service_node:1.21"> | 32 | ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service_node:1.21"> |
33 | ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·1.21</cpe-dict:title> | 33 | ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·1.21</cpe-dict:title> |
Offset 35, 15 lines modified | Offset 35, 15 lines modified | ||
35 | ······</cpe-dict:cpe-item> | 35 | ······</cpe-dict:cpe-item> |
36 | ······<cpe-dict:cpe-item·name="cpe:/o:amazon:elastic_kubernetes_service_node:1"> | 36 | ······<cpe-dict:cpe-item·name="cpe:/o:amazon:elastic_kubernetes_service_node:1"> |
37 | ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title> | 37 | ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title> |
38 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check> | 38 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check> |
39 | ······</cpe-dict:cpe-item> | 39 | ······</cpe-dict:cpe-item> |
40 | ····</cpe-dict:cpe-list> | 40 | ····</cpe-dict:cpe-list> |
41 | ··</ds:component> | 41 | ··</ds:component> |
42 | ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2025-0 | 42 | ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
43 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 43 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
44 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 44 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
45 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title> | 45 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title> |
46 | ······<xccdf-1.2:description> | 46 | ······<xccdf-1.2:description> |
47 | ········This·guide·presents·a·catalog·of·security-relevant | 47 | ········This·guide·presents·a·catalog·of·security-relevant |
48 | configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of | 48 | configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of |
49 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 49 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 1545, 15 lines modified | Offset 1545, 15 lines modified | ||
1545 | ··············<xccdf-1.2:check-content-ref·href="ssg-eks-ocil.xml"·name="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"/> | 1545 | ··············<xccdf-1.2:check-content-ref·href="ssg-eks-ocil.xml"·name="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"/> |
1546 | ············</xccdf-1.2:check> | 1546 | ············</xccdf-1.2:check> |
1547 | ··········</xccdf-1.2:Rule> | 1547 | ··········</xccdf-1.2:Rule> |
1548 | ········</xccdf-1.2:Group> | 1548 | ········</xccdf-1.2:Group> |
1549 | ······</xccdf-1.2:Group> | 1549 | ······</xccdf-1.2:Group> |
1550 | ····</xccdf-1.2:Benchmark> | 1550 | ····</xccdf-1.2:Benchmark> |
1551 | ··</ds:component> | 1551 | ··</ds:component> |
1552 | ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-oval.xml"·timestamp="2025-0 | 1552 | ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-oval.xml"·timestamp="2025-03-01T22:08:00"> |
1553 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 1553 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
1554 | ······<oval-def:generator> | 1554 | ······<oval-def:generator> |
1555 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 1555 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
1556 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 1556 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
1557 | ········<oval:schema_version>5.11</oval:schema_version> | 1557 | ········<oval:schema_version>5.11</oval:schema_version> |
1558 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 1558 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
1559 | ······</oval-def:generator> | 1559 | ······</oval-def:generator> |
Offset 2166, 330 lines modified | Offset 2166, 330 lines modified | ||
2166 | ········<oval-def:external_variable·id="oval:ssg-var_streaming_connection_timeouts:var:1"·version="1"·datatype="string"·comment="variable"/> | 2166 | ········<oval-def:external_variable·id="oval:ssg-var_streaming_connection_timeouts:var:1"·version="1"·datatype="string"·comment="variable"/> |
2167 | ········<oval-def:local_variable·id="oval:ssg-kubelet_read_only_port_secured_file_location:var:1"·version="1"·datatype="string"·comment="The·actual·path·of·the·file·to·scan."> | 2167 | ········<oval-def:local_variable·id="oval:ssg-kubelet_read_only_port_secured_file_location:var:1"·version="1"·datatype="string"·comment="The·actual·path·of·the·file·to·scan."> |
2168 | ··········<oval-def:literal_component>/etc/kubernetes/compliance-operator/kubeletconfig/openscap-kubeletconfig</oval-def:literal_component> | 2168 | ··········<oval-def:literal_component>/etc/kubernetes/compliance-operator/kubeletconfig/openscap-kubeletconfig</oval-def:literal_component> |
2169 | ········</oval-def:local_variable> | 2169 | ········</oval-def:local_variable> |
2170 | ······</oval-def:variables> | 2170 | ······</oval-def:variables> |
2171 | ····</oval-def:oval_definitions> | 2171 | ····</oval-def:oval_definitions> |
2172 | ··</ds:component> | 2172 | ··</ds:component> |
2173 | ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-ocil.xml"·timestamp="2025-0 | 2173 | ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
2174 | ····<ocil:ocil> | 2174 | ····<ocil:ocil> |
2175 | ······<ocil:generator> | 2175 | ······<ocil:generator> |
2176 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 2176 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
2177 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 2177 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
2178 | ········<ocil:schema_version>2.0</ocil:schema_version> | 2178 | ········<ocil:schema_version>2.0</ocil:schema_version> |
2179 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 2179 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
2180 | ······</ocil:generator> | 2180 | ······</ocil:generator> |
2181 | ······<ocil:questionnaires> | 2181 | ······<ocil:questionnaires> |
2182 | ········<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1"> | ||
2183 | ··········<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title> | ||
2184 | ··········<ocil:actions> | ||
2185 | ············<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref> | ||
2186 | ··········</ocil:actions> | ||
2187 | ········</ocil:questionnaire> | ||
2188 | ········<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1"> | 2182 | ········<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1"> |
2189 | ··········<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title> | 2183 | ··········<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title> |
2190 | ··········<ocil:actions> | 2184 | ··········<ocil:actions> |
2191 | ············<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref> | 2185 | ············<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref> |
2192 | ··········</ocil:actions> | 2186 | ··········</ocil:actions> |
2193 | ········</ocil:questionnaire> | 2187 | ········</ocil:questionnaire> |
2194 | ········<ocil:questionnaire·id="ocil:ssg- | 2188 | ········<ocil:questionnaire·id="ocil:ssg-approved_registries_ocil:questionnaire:1"> |
2195 | ··········<ocil:title> | 2189 | ··········<ocil:title>Only·use·approved·container·registries</ocil:title> |
2196 | ··········<ocil:actions> | 2190 | ··········<ocil:actions> |
2197 | ············<ocil:test_action_ref>ocil:ssg- | 2191 | ············<ocil:test_action_ref>ocil:ssg-approved_registries_action:testaction:1</ocil:test_action_ref> |
2198 | ··········</ocil:actions> | 2192 | ··········</ocil:actions> |
2199 | ········</ocil:questionnaire> | 2193 | ········</ocil:questionnaire> |
2200 | ········<ocil:questionnaire·id="ocil:ssg-file_ow | 2194 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"> |
2201 | ··········<ocil:title>Verify· | 2195 | ··········<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title> |
2202 | ··········<ocil:actions> | 2196 | ··········<ocil:actions> |
2197 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref> | ||
2198 | ··········</ocil:actions> | ||
2199 | ········</ocil:questionnaire> | ||
2200 | ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_server_cert_rotation_ocil:questionnaire:1"> | ||
2201 | ··········<ocil:title>kubelet·-·Enable·Server·Certificate·Rotation</ocil:title> | ||
2202 | ··········<ocil:actions> | ||
2203 | ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_server_cert_rotation_action:testaction:1</ocil:test_action_ref> | ||
2204 | ··········</ocil:actions> | ||
2205 | ········</ocil:questionnaire> | ||
2206 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1"> | ||
2207 | ··········<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title> | ||
2208 | ··········<ocil:actions> | ||
2203 | ············<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref> | 2209 | ············<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref> |
2204 | ··········</ocil:actions> | 2210 | ··········</ocil:actions> |
2205 | ········</ocil:questionnaire> | 2211 | ········</ocil:questionnaire> |
2206 | ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_ocil:questionnaire:1"> | 2212 | ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_ocil:questionnaire:1"> |
2207 | ··········<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title> | 2213 | ··········<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title> |
2208 | ··········<ocil:actions> | 2214 | ··········<ocil:actions> |
2209 | ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_action:testaction:1</ocil:test_action_ref> | 2215 | ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_action:testaction:1</ocil:test_action_ref> |
2210 | ··········</ocil:actions> | 2216 | ··········</ocil:actions> |
2211 | ········</ocil:questionnaire> | 2217 | ········</ocil:questionnaire> |
2212 | ········<ocil:questionnaire·id="ocil:ssg- | 2218 | ········<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1"> |
2213 | ··········<ocil:title> | 2219 | ··········<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title> |
2214 | ··········<ocil:actions> | 2220 | ··········<ocil:actions> |
2215 | ············<ocil:test_action_ref>ocil:ssg- | 2221 | ············<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref> |
2216 | ··········</ocil:actions> | 2222 | ··········</ocil:actions> |
2217 | ········</ocil:questionnaire> | 2223 | ········</ocil:questionnaire> |
2218 | ········<ocil:questionnaire·id="ocil:ssg-i | 2224 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_kubelet_conf_ocil:questionnaire:1"> |
2219 | ··········<ocil:title> | 2225 | ··········<ocil:title>Verify·Permissions·on·The·Kubelet·Configuration·File</ocil:title> |
2220 | ··········<ocil:actions> | 2226 | ··········<ocil:actions> |
2221 | ············<ocil:test_action_ref>ocil:ssg-i | 2227 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_kubelet_conf_action:testaction:1</ocil:test_action_ref> |
2222 | ··········</ocil:actions> | 2228 | ··········</ocil:actions> |
2223 | ········</ocil:questionnaire> | 2229 | ········</ocil:questionnaire> |
2224 | ········<ocil:questionnaire·id="ocil:ssg- | 2230 | ········<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1"> |
2225 | ··········<ocil:title> | 2231 | ··········<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title> |
2226 | ··········<ocil:actions> | 2232 | ··········<ocil:actions> |
2227 | ············<ocil:test_action_ref>ocil:ssg- | 2233 | ············<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref> |
2228 | ··········</ocil:actions> | 2234 | ··········</ocil:actions> |
2229 | ········</ocil:questionnaire> | 2235 | ········</ocil:questionnaire> |
2230 | ········<ocil:questionnaire·id="ocil:ssg- | 2236 | ········<ocil:questionnaire·id="ocil:ssg-fargate_ocil:questionnaire:1"> |
2231 | ··········<ocil:title> | 2237 | ··········<ocil:title>Consider·Fargate·for·Untrusted·Workloads</ocil:title> |
2232 | ··········<ocil:actions> | 2238 | ··········<ocil:actions> |
Max diff block lines reached; 67983/79679 bytes (85.32%) of diff not shown. |
Offset 3, 321 lines modified | Offset 3, 321 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1"> | ||
11 | ······<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1"> | 10 | ····<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1"> |
17 | ······<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title> | 11 | ······<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title> |
18 | ······<ocil:actions> | 12 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref> | 13 | ········<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 14 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1"> | ||
23 | ···· | 16 | ····<ocil:questionnaire·id="ocil:ssg-approved_registries_ocil:questionnaire:1"> |
17 | ······<ocil:title>Only·use·approved·container·registries</ocil:title> | ||
24 | ······<ocil:actions> | 18 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-approved_registries_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 20 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-file_ow | 22 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"> |
29 | ······<ocil:title>Verify· | 23 | ······<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title> |
30 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref> | ||
26 | ······</ocil:actions> | ||
27 | ····</ocil:questionnaire> | ||
28 | ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_server_cert_rotation_ocil:questionnaire:1"> | ||
29 | ······<ocil:title>kubelet·-·Enable·Server·Certificate·Rotation</ocil:title> | ||
30 | ······<ocil:actions> | ||
31 | ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_server_cert_rotation_action:testaction:1</ocil:test_action_ref> | ||
32 | ······</ocil:actions> | ||
33 | ····</ocil:questionnaire> | ||
34 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1"> | ||
35 | ······<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title> | ||
36 | ······<ocil:actions> | ||
31 | ········<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref> | 37 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 38 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_ocil:questionnaire:1"> | 40 | ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_ocil:questionnaire:1"> |
35 | ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title> | 41 | ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title> |
36 | ······<ocil:actions> | 42 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_action:testaction:1</ocil:test_action_ref> | 43 | ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 44 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 46 | ····<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 47 | ······<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title> |
42 | ······<ocil:actions> | 48 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 50 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-i | 52 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_kubelet_conf_ocil:questionnaire:1"> |
47 | ······<ocil:title> | 53 | ······<ocil:title>Verify·Permissions·on·The·Kubelet·Configuration·File</ocil:title> |
48 | ······<ocil:actions> | 54 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg-i | 55 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_kubelet_conf_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 56 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 59 | ······<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title> |
54 | ······<ocil:actions> | 60 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 62 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-fargate_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 65 | ······<ocil:title>Consider·Fargate·for·Untrusted·Workloads</ocil:title> |
60 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg-fargate_action:testaction:1</ocil:test_action_ref> | ||
68 | ······</ocil:actions> | ||
69 | ····</ocil:questionnaire> | ||
70 | ····<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_ocil:questionnaire:1"> | ||
71 | ······<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title> | ||
72 | ······<ocil:actions> | ||
61 | ········<ocil:test_action_ref>ocil:ssg-kubelet_ | 73 | ········<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | ||
75 | ····</ocil:questionnaire> | ||
76 | ····<ocil:questionnaire·id="ocil:ssg-control_plane_access_ocil:questionnaire:1"> | ||
77 | ······<ocil:title>Restrict·Access·to·the·Control·Plane·Endpoint</ocil:title> | ||
78 | ······<ocil:actions> | ||
79 | ········<ocil:test_action_ref>ocil:ssg-control_plane_access_action:testaction:1</ocil:test_action_ref> | ||
62 | ······</ocil:actions> | 80 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1"> | 82 | ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1"> |
65 | ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title> | 83 | ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title> |
66 | ······<ocil:actions> | 84 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref> | 85 | ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 86 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1"> | ||
89 | ······<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title> | ||
90 | ······<ocil:actions> | ||
91 | ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref> | ||
92 | ······</ocil:actions> | ||
93 | ····</ocil:questionnaire> | ||
70 | ····<ocil:questionnaire·id="ocil:ssg-audit_logging_ocil:questionnaire:1"> | 94 | ····<ocil:questionnaire·id="ocil:ssg-audit_logging_ocil:questionnaire:1"> |
71 | ······<ocil:title>Ensure·Audit·Logging·is·Enabled</ocil:title> | 95 | ······<ocil:title>Ensure·Audit·Logging·is·Enabled</ocil:title> |
72 | ······<ocil:actions> | 96 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg-audit_logging_action:testaction:1</ocil:test_action_ref> | 97 | ········<ocil:test_action_ref>ocil:ssg-audit_logging_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 98 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1"> |
77 | ······<ocil:title> | 101 | ······<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title> |
78 | ······<ocil:actions> | 102 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 104 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg- | 106 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_conf_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 107 | ······<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title> |
84 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref> | ||
110 | ······</ocil:actions> | ||
111 | ····</ocil:questionnaire> | ||
112 | ····<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1"> | ||
113 | ······<ocil:title>Ensure·Private·Endpoint·Access</ocil:title> | ||
114 | ······<ocil:actions> | ||
115 | ········<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref> | ||
116 | ······</ocil:actions> | ||
117 | ····</ocil:questionnaire> | ||
118 | ····<ocil:questionnaire·id="ocil:ssg-private_nodes_ocil:questionnaire:1"> | ||
119 | ······<ocil:title>Ensure·Cluster·Private·Nodes</ocil:title> | ||
120 | ······<ocil:actions> | ||
85 | ········<ocil:test_action_ref>ocil:ssg- | 121 | ········<ocil:test_action_ref>ocil:ssg-private_nodes_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 122 | ······</ocil:actions> |
Max diff block lines reached; 61525/70903 bytes (86.77%) of diff not shown. |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/a:mozilla:firefox"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/a:mozilla:firefox"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Firefox.·It·is·a·rendering·of | 40 | configuration·settings·for·Firefox.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 3488, 15 lines modified | Offset 3488, 15 lines modified | ||
3488 | ··············<xccdf-1.2:check-content-ref·href="ssg-firefox-ocil.xml"·name="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"/> | 3488 | ··············<xccdf-1.2:check-content-ref·href="ssg-firefox-ocil.xml"·name="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"/> |
3489 | ············</xccdf-1.2:check> | 3489 | ············</xccdf-1.2:check> |
3490 | ··········</xccdf-1.2:Rule> | 3490 | ··········</xccdf-1.2:Rule> |
3491 | ········</xccdf-1.2:Group> | 3491 | ········</xccdf-1.2:Group> |
3492 | ······</xccdf-1.2:Group> | 3492 | ······</xccdf-1.2:Group> |
3493 | ····</xccdf-1.2:Benchmark> | 3493 | ····</xccdf-1.2:Benchmark> |
3494 | ··</ds:component> | 3494 | ··</ds:component> |
3495 | ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-oval.xml"·timestamp="2025-0 | 3495 | ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-oval.xml"·timestamp="2025-03-01T22:08:00"> |
3496 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 3496 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
3497 | ······<oval-def:generator> | 3497 | ······<oval-def:generator> |
3498 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 3498 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
3499 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 3499 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
3500 | ········<oval:schema_version>5.11</oval:schema_version> | 3500 | ········<oval:schema_version>5.11</oval:schema_version> |
3501 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 3501 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
3502 | ······</oval-def:generator> | 3502 | ······</oval-def:generator> |
Offset 5198, 304 lines modified | Offset 5198, 304 lines modified | ||
5198 | ··············<oval-def:literal_component>/distribution</oval-def:literal_component> | 5198 | ··············<oval-def:literal_component>/distribution</oval-def:literal_component> |
5199 | ············</oval-def:concat> | 5199 | ············</oval-def:concat> |
5200 | ··········</oval-def:unique> | 5200 | ··········</oval-def:unique> |
5201 | ········</oval-def:local_variable> | 5201 | ········</oval-def:local_variable> |
5202 | ······</oval-def:variables> | 5202 | ······</oval-def:variables> |
5203 | ····</oval-def:oval_definitions> | 5203 | ····</oval-def:oval_definitions> |
5204 | ··</ds:component> | 5204 | ··</ds:component> |
5205 | ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-ocil.xml"·timestamp="2025-0 | 5205 | ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
5206 | ····<ocil:ocil> | 5206 | ····<ocil:ocil> |
5207 | ······<ocil:generator> | 5207 | ······<ocil:generator> |
5208 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 5208 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5209 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5209 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
5210 | ········<ocil:schema_version>2.0</ocil:schema_version> | 5210 | ········<ocil:schema_version>2.0</ocil:schema_version> |
5211 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 5211 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
5212 | ······</ocil:generator> | 5212 | ······</ocil:generator> |
5213 | ······<ocil:questionnaires> | 5213 | ······<ocil:questionnaires> |
5214 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy- | 5214 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1"> |
5215 | ··········<ocil:title>Disable·Firefox·Pocket</ocil:title> | ||
5215 | ··········<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title> | ||
5216 | ··········<ocil:actions> | ||
5217 | ············<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref> | ||
5218 | ··········</ocil:actions> | ||
5219 | ········</ocil:questionnaire> | ||
5220 | ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"> | ||
5221 | ··········<ocil:title>Enable·Shared·System·Certificates</ocil:title> | ||
5222 | ··········<ocil:actions> | 5216 | ··········<ocil:actions> |
5223 | ············<ocil:test_action_ref>ocil:ssg-firefox_p | 5217 | ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref> |
5224 | ··········</ocil:actions> | 5218 | ··········</ocil:actions> |
5225 | ········</ocil:questionnaire> | 5219 | ········</ocil:questionnaire> |
5226 | ········<ocil:questionnaire·id="ocil:ssg-firefox_p | 5220 | ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1"> |
5227 | ··········<ocil:title> | 5221 | ··········<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title> |
5228 | ··········<ocil:actions> | 5222 | ··········<ocil:actions> |
5229 | ············<ocil:test_action_ref>ocil:ssg-firefox_p | 5223 | ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref> |
5230 | ··········</ocil:actions> | 5224 | ··········</ocil:actions> |
5231 | ········</ocil:questionnaire> | 5225 | ········</ocil:questionnaire> |
5232 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-p | 5226 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1"> |
5233 | ··········<ocil:title> | 5227 | ··········<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title> |
5234 | ··········<ocil:actions> | 5228 | ··········<ocil:actions> |
5235 | ············<ocil:test_action_ref>ocil:ssg-firefox_policy-p | 5229 | ············<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref> |
5236 | ··········</ocil:actions> | 5230 | ··········</ocil:actions> |
5237 | ········</ocil:questionnaire> | 5231 | ········</ocil:questionnaire> |
5238 | ········<ocil:questionnaire·id="ocil:ssg- | 5232 | ········<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1"> |
5239 | ··········<ocil:title> | 5233 | ··········<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title> |
5240 | ··········<ocil:actions> | 5234 | ··········<ocil:actions> |
5241 | ············<ocil:test_action_ref>ocil:ssg- | 5235 | ············<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref> |
5242 | ··········</ocil:actions> | 5236 | ··········</ocil:actions> |
5243 | ········</ocil:questionnaire> | 5237 | ········</ocil:questionnaire> |
5244 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy- | 5238 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1"> |
5245 | ··········<ocil:title>Disable | 5239 | ··········<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title> |
5246 | ··········<ocil:actions> | 5240 | ··········<ocil:actions> |
5247 | ············<ocil:test_action_ref>ocil:ssg-firefox_policy- | 5241 | ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref> |
5248 | ··········</ocil:actions> | 5242 | ··········</ocil:actions> |
5249 | ········</ocil:questionnaire> | 5243 | ········</ocil:questionnaire> |
5250 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1"> | 5244 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1"> |
5251 | ··········<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title> | 5245 | ··········<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title> |
5252 | ··········<ocil:actions> | 5246 | ··········<ocil:actions> |
5253 | ············<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref> | 5247 | ············<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref> |
5254 | ··········</ocil:actions> | 5248 | ··········</ocil:actions> |
5255 | ········</ocil:questionnaire> | 5249 | ········</ocil:questionnaire> |
5256 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy- | 5250 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1"> |
5251 | ··········<ocil:title>Enable·Certificate·Verification</ocil:title> | ||
5257 | ··········<ocil:title>Disable·Installed·Search·Plugins·Update·Checking</ocil:title> | ||
5258 | ··········<ocil:actions> | ||
5259 | ············<ocil:test_action_ref>ocil:ssg-firefox_policy-search_update_action:testaction:1</ocil:test_action_ref> | ||
5260 | ··········</ocil:actions> | ||
5261 | ········</ocil:questionnaire> | ||
5262 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1"> | ||
5263 | ··········<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title> | ||
5264 | ··········<ocil:actions> | 5252 | ··········<ocil:actions> |
5265 | ············<ocil:test_action_ref>ocil:ssg-firefox_policy- | 5253 | ············<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref> |
5266 | ··········</ocil:actions> | 5254 | ··········</ocil:actions> |
5267 | ········</ocil:questionnaire> | 5255 | ········</ocil:questionnaire> |
5268 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_ | 5256 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1"> |
5269 | ··········<ocil:title>Disable·JavaScript's· | 5257 | ··········<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title> |
5270 | ··········<ocil:actions> | 5258 | ··········<ocil:actions> |
5271 | ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_ | 5259 | ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref> |
5272 | ··········</ocil:actions> | 5260 | ··········</ocil:actions> |
5273 | ········</ocil:questionnaire> | 5261 | ········</ocil:questionnaire> |
5274 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy- | 5262 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1"> |
5275 | ··········<ocil:title> | 5263 | ··········<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title> |
5276 | ··········<ocil:actions> | 5264 | ··········<ocil:actions> |
5277 | ············<ocil:test_action_ref>ocil:ssg-firefox_policy- | 5265 | ············<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref> |
5278 | ··········</ocil:actions> | 5266 | ··········</ocil:actions> |
5279 | ········</ocil:questionnaire> | 5267 | ········</ocil:questionnaire> |
5280 | ········<ocil:questionnaire·id="ocil:ssg-firefox_p | 5268 | ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1"> |
5281 | ··········<ocil:title> | 5269 | ··········<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title> |
5282 | ··········<ocil:actions> | 5270 | ··········<ocil:actions> |
Max diff block lines reached; 45320/56901 bytes (79.65%) of diff not shown. |
Offset 3, 295 lines modified | Offset 3, 295 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy- | 10 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1"> |
11 | ······<ocil:title>Disable·Firefox·Pocket</ocil:title> | ||
11 | ······<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"> | ||
17 | ······<ocil:title>Enable·Shared·System·Certificates</ocil:title> | ||
18 | ······<ocil:actions> | 12 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg-firefox_p | 13 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 14 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg-firefox_p | 16 | ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1"> |
23 | ······<ocil:title> | 17 | ······<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title> |
24 | ······<ocil:actions> | 18 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg-firefox_p | 19 | ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 20 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-p | 22 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1"> |
29 | ······<ocil:title> | 23 | ······<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title> |
30 | ······<ocil:actions> | 24 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-p | 25 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 26 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1"> | ||
35 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1"> |
29 | ······<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title> | ||
36 | ······<ocil:actions> | 30 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 32 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy- | 34 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1"> |
41 | ······<ocil:title>Disable | 35 | ······<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title> |
42 | ······<ocil:actions> | 36 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy- | 37 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 38 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1"> | 40 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1"> |
47 | ······<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title> | 41 | ······<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title> |
48 | ······<ocil:actions> | 42 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref> | 43 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 44 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy- | 46 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1"> |
47 | ······<ocil:title>Enable·Certificate·Verification</ocil:title> | ||
53 | ······<ocil:title>Disable·Installed·Search·Plugins·Update·Checking</ocil:title> | ||
54 | ······<ocil:actions> | ||
55 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_update_action:testaction:1</ocil:test_action_ref> | ||
56 | ······</ocil:actions> | ||
57 | ····</ocil:questionnaire> | ||
58 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1"> | ||
59 | ······<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title> | ||
60 | ······<ocil:actions> | 48 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy- | 49 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 50 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_ | 52 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1"> |
65 | ······<ocil:title>Disable·JavaScript's· | 53 | ······<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title> |
66 | ······<ocil:actions> | 54 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_ | 55 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 56 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy- | 58 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 59 | ······<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title> |
72 | ······<ocil:actions> | 60 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy- | 61 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 62 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-firefox_p | 64 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1"> |
77 | ······<ocil:title> | 65 | ······<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title> |
78 | ······<ocil:actions> | 66 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg-firefox_p | 67 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 68 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-firefox_p | 70 | ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-dod_root_certificate_installed_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 71 | ······<ocil:title>The·DoD·Root·Certificate·Exists</ocil:title> |
84 | ······<ocil:actions> | 72 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg-firefox_p | 73 | ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-dod_root_certificate_installed_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 74 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy- | 76 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 77 | ······<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title> |
90 | ······<ocil:actions> | 78 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy- | 79 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 80 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1"> | 82 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1"> |
95 | ······<ocil:title>Disable·Firefox·Development·Tools</ocil:title> | 83 | ······<ocil:title>Disable·Firefox·Development·Tools</ocil:title> |
96 | ······<ocil:actions> | 84 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref> | 85 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 86 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy- | 88 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1"> |
101 | ······<ocil:title>En | 89 | ······<ocil:title>Ensure·the·Content·Blocker·uBlock·Origin·is·Installed</ocil:title> |
102 | ······<ocil:actions> | 90 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy- | 91 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-content_blocker_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 92 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-firefox_p | 94 | ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 95 | ······<ocil:title>Enable·Shared·System·Certificates</ocil:title> |
108 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref> | ||
98 | ······</ocil:actions> | ||
99 | ····</ocil:questionnaire> | ||
100 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1"> | ||
101 | ······<ocil:title>Disable·Firefox·network·prediction</ocil:title> | ||
102 | ······<ocil:actions> | ||
109 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy- | 103 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | ||
105 | ····</ocil:questionnaire> | ||
106 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1"> | ||
107 | ······<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title> | ||
108 | ······<ocil:actions> | ||
109 | ········<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref> | ||
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1"> | 112 | ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1"> |
113 | ······<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title> | 113 | ······<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title> |
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
Max diff block lines reached; 38371/49637 bytes (77.30%) of diff not shown. |
Offset 1, 3 lines modified | Offset 1, 3 lines modified | ||
1 | -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary | 1 | -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary |
2 | -rw-r--r--···0········0········0·····3044·2025-03-01·08:08:00.000000·control.tar.xz | 2 | -rw-r--r--···0········0········0·····3044·2025-03-01·08:08:00.000000·control.tar.xz |
3 | -rw-r--r--···0········0········0··3722 | 3 | -rw-r--r--···0········0········0··3722616·2025-03-01·08:08:00.000000·data.tar.xz |
Offset 21, 23 lines modified | Offset 21, 23 lines modified | ||
21 | ····<ds:checks> | 21 | ····<ds:checks> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"/> |
24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-cpe-oval.xml"/> | 24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-cpe-oval.xml"/> |
25 | ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.xenial.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.xenial.usn.oval.xml.bz2"/> | 25 | ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.xenial.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.xenial.usn.oval.xml.bz2"/> |
26 | ····</ds:checks> | 26 | ····</ds:checks> |
27 | ··</ds:data-stream> | 27 | ··</ds:data-stream> |
28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-cpe-dictionary.xml"·timestamp="2025-0 | 28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
30 | ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~"> | 30 | ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~"> |
31 | ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·16.04·(Xenial)</cpe-dict:title> | 31 | ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·16.04·(Xenial)</cpe-dict:title> |
32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1604:def:1</cpe-dict:check> | 32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1604:def:1</cpe-dict:check> |
33 | ······</cpe-dict:cpe-item> | 33 | ······</cpe-dict:cpe-item> |
34 | ····</cpe-dict:cpe-list> | 34 | ····</cpe-dict:cpe-list> |
35 | ··</ds:component> | 35 | ··</ds:component> |
36 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-xccdf.xml"·timestamp="2025-0 | 36 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
37 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 37 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
38 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 38 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
39 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title> | 39 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title> |
40 | ······<xccdf-1.2:description> | 40 | ······<xccdf-1.2:description> |
41 | ········This·guide·presents·a·catalog·of·security-relevant | 41 | ········This·guide·presents·a·catalog·of·security-relevant |
42 | configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of | 42 | configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of |
43 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 43 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 63230, 15 lines modified | Offset 63230, 15 lines modified | ||
63230 | ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1604-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> | 63230 | ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1604-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> |
63231 | ············</xccdf-1.2:check> | 63231 | ············</xccdf-1.2:check> |
63232 | ··········</xccdf-1.2:Rule> | 63232 | ··········</xccdf-1.2:Rule> |
63233 | ········</xccdf-1.2:Group> | 63233 | ········</xccdf-1.2:Group> |
63234 | ······</xccdf-1.2:Group> | 63234 | ······</xccdf-1.2:Group> |
63235 | ····</xccdf-1.2:Benchmark> | 63235 | ····</xccdf-1.2:Benchmark> |
63236 | ··</ds:component> | 63236 | ··</ds:component> |
63237 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"·timestamp="2025-0 | 63237 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"·timestamp="2025-03-01T22:08:00"> |
63238 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 63238 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
63239 | ······<oval-def:generator> | 63239 | ······<oval-def:generator> |
63240 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 63240 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
63241 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 63241 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
63242 | ········<oval:schema_version>5.11</oval:schema_version> | 63242 | ········<oval:schema_version>5.11</oval:schema_version> |
63243 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 63243 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
63244 | ······</oval-def:generator> | 63244 | ······</oval-def:generator> |
Offset 79818, 4346 lines modified | Offset 79818, 4346 lines modified | ||
79818 | ············</oval-def:arithmetic> | 79818 | ············</oval-def:arithmetic> |
79819 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 79819 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
79820 | ··········</oval-def:arithmetic> | 79820 | ··········</oval-def:arithmetic> |
79821 | ········</oval-def:local_variable> | 79821 | ········</oval-def:local_variable> |
79822 | ······</oval-def:variables> | 79822 | ······</oval-def:variables> |
79823 | ····</oval-def:oval_definitions> | 79823 | ····</oval-def:oval_definitions> |
79824 | ··</ds:component> | 79824 | ··</ds:component> |
79825 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"·timestamp="2025-0 | 79825 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
79826 | ····<ocil:ocil> | 79826 | ····<ocil:ocil> |
79827 | ······<ocil:generator> | 79827 | ······<ocil:generator> |
79828 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 79828 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
79829 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 79829 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
79830 | ········<ocil:schema_version>2.0</ocil:schema_version> | 79830 | ········<ocil:schema_version>2.0</ocil:schema_version> |
79831 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 79831 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
79832 | ······</ocil:generator> | 79832 | ······</ocil:generator> |
79833 | ······<ocil:questionnaires> | 79833 | ······<ocil:questionnaires> |
79834 | ········<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1"> | ||
79835 | ··········<ocil:title>Set·Password·Minimum·Age</ocil:title> | ||
79836 | ··········<ocil:actions> | ||
79837 | ············<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref> | ||
79838 | ··········</ocil:actions> | ||
79839 | ········</ocil:questionnaire> | ||
79840 | ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1"> | ||
79841 | ··········<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title> | ||
79842 | ··········<ocil:actions> | ||
79843 | ············<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref> | ||
79844 | ··········</ocil:actions> | ||
79845 | ········</ocil:questionnaire> | ||
79846 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> | ||
79847 | ··········<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title> | ||
79848 | ··········<ocil:actions> | ||
79849 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref> | ||
79850 | ··········</ocil:actions> | ||
79851 | ········</ocil:questionnaire> | ||
79852 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_ | 79834 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1"> |
79853 | ··········<ocil:title> | 79835 | ··········<ocil:title>Enable·module·signature·verification</ocil:title> |
79854 | ··········<ocil:actions> | 79836 | ··········<ocil:actions> |
79855 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_ | 79837 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref> |
79856 | ··········</ocil:actions> | 79838 | ··········</ocil:actions> |
79857 | ········</ocil:questionnaire> | 79839 | ········</ocil:questionnaire> |
79858 | ········<ocil:questionnaire·id="ocil:ssg- | 79840 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1"> |
79859 | ··········<ocil:title> | 79841 | ··········<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title> |
79860 | ··········<ocil:actions> | 79842 | ··········<ocil:actions> |
79861 | ············<ocil:test_action_ref>ocil:ssg- | 79843 | ············<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref> |
79862 | ··········</ocil:actions> | 79844 | ··········</ocil:actions> |
79863 | ········</ocil:questionnaire> | 79845 | ········</ocil:questionnaire> |
79864 | ········<ocil:questionnaire·id="ocil:ssg- | 79846 | ········<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1"> |
79865 | ··········<ocil:title>En | 79847 | ··········<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title> |
79866 | ··········<ocil:actions> | 79848 | ··········<ocil:actions> |
79867 | ············<ocil:test_action_ref>ocil:ssg- | 79849 | ············<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref> |
79868 | ··········</ocil:actions> | 79850 | ··········</ocil:actions> |
79869 | ········</ocil:questionnaire> | 79851 | ········</ocil:questionnaire> |
79870 | ········<ocil:questionnaire·id="ocil:ssg- | 79852 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1"> |
79871 | ··········<ocil:title>Disable· | 79853 | ··········<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title> |
79872 | ··········<ocil:actions> | 79854 | ··········<ocil:actions> |
79873 | ············<ocil:test_action_ref>ocil:ssg- | 79855 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref> |
79874 | ··········</ocil:actions> | 79856 | ··········</ocil:actions> |
79875 | ········</ocil:questionnaire> | 79857 | ········</ocil:questionnaire> |
79876 | ········<ocil:questionnaire·id="ocil:ssg-s | 79858 | ········<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1"> |
79877 | ··········<ocil:title>En | 79859 | ··········<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title> |
79878 | ··········<ocil:actions> | 79860 | ··········<ocil:actions> |
79879 | ············<ocil:test_action_ref>ocil:ssg-s | 79861 | ············<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref> |
79880 | ··········</ocil:actions> | 79862 | ··········</ocil:actions> |
79881 | ········</ocil:questionnaire> | 79863 | ········</ocil:questionnaire> |
79882 | ········<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1"> | 79864 | ········<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1"> |
79883 | ··········<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title> | 79865 | ··········<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title> |
79884 | ··········<ocil:actions> | 79866 | ··········<ocil:actions> |
79885 | ············<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref> | 79867 | ············<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref> |
79886 | ··········</ocil:actions> | 79868 | ··········</ocil:actions> |
79887 | ········</ocil:questionnaire> | 79869 | ········</ocil:questionnaire> |
79888 | ········<ocil:questionnaire·id="ocil:ssg-a | 79870 | ········<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1"> |
79871 | ··········<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title> | ||
79889 | ··········<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title> | ||
79890 | ··········<ocil:actions> | ||
79891 | ············<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref> | ||
79892 | ··········</ocil:actions> | ||
79893 | ········</ocil:questionnaire> | ||
79894 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1"> | ||
79895 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title> | ||
79896 | ··········<ocil:actions> | 79872 | ··········<ocil:actions> |
79897 | ············<ocil:test_action_ref>ocil:ssg-audit | 79873 | ············<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref> |
79898 | ··········</ocil:actions> | 79874 | ··········</ocil:actions> |
79899 | ········</ocil:questionnaire> | 79875 | ········</ocil:questionnaire> |
79900 | ········<ocil:questionnaire·id="ocil:ssg-no_em | 79876 | ········<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1"> |
79901 | ··········<ocil:title> | 79877 | ··········<ocil:title>Do·Not·Allow·SSH·Environment·Options</ocil:title> |
79902 | ··········<ocil:actions> | 79878 | ··········<ocil:actions> |
79903 | ············<ocil:test_action_ref>ocil:ssg-no_em | 79879 | ············<ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref> |
Max diff block lines reached; 701676/712562 bytes (98.47%) of diff not shown. |
Offset 3, 4337 lines modified | Offset 3, 4337 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1"> | ||
11 | ······<ocil:title>Set·Password·Minimum·Age</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1"> | ||
17 | ······<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title> | ||
18 | ······<ocil:actions> | ||
19 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref> | ||
20 | ······</ocil:actions> | ||
21 | ····</ocil:questionnaire> | ||
22 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> | ||
23 | ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title> | ||
24 | ······<ocil:actions> | ||
25 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref> | ||
26 | ······</ocil:actions> | ||
27 | ····</ocil:questionnaire> | ||
28 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ | 10 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1"> |
29 | ······<ocil:title> | 11 | ······<ocil:title>Enable·module·signature·verification</ocil:title> |
30 | ······<ocil:actions> | 12 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_ | 13 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 14 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg- | 16 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1"> |
35 | ······<ocil:title> | 17 | ······<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title> |
36 | ······<ocil:actions> | 18 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 20 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1"> |
41 | ······<ocil:title>En | 23 | ······<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title> |
42 | ······<ocil:actions> | 24 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 26 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg- | 28 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1"> |
47 | ······<ocil:title>Disable· | 29 | ······<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title> |
48 | ······<ocil:actions> | 30 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 32 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1"> | ||
53 | ···· | 34 | ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1"> |
35 | ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title> | ||
54 | ······<ocil:actions> | 36 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg-s | 37 | ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 38 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1"> | 40 | ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1"> |
59 | ······<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title> | 41 | ······<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title> |
60 | ······<ocil:actions> | 42 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref> | 43 | ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 44 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-a | 46 | ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1"> |
47 | ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title> | ||
65 | ······<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title> | ||
66 | ······<ocil:actions> | ||
67 | ········<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref> | ||
68 | ······</ocil:actions> | ||
69 | ····</ocil:questionnaire> | ||
70 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1"> | ||
71 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title> | ||
72 | ······<ocil:actions> | 48 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg-audit | 49 | ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 50 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-no_em | 52 | ····<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1"> |
77 | ······<ocil:title> | 53 | ······<ocil:title>Do·Not·Allow·SSH·Environment·Options</ocil:title> |
78 | ······<ocil:actions> | 54 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg-no_em | 55 | ········<ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 56 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 59 | ······<ocil:title>Ensure·LDAP·client·is·not·installed</ocil:title> |
84 | ······<ocil:actions> | 60 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-package_openldap-clients_removed_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 62 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-se | 64 | ····<ocil:questionnaire·id="ocil:ssg-service_timesyncd_enabled_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 65 | ······<ocil:title>Enable·systemd_timesyncd·Service</ocil:title> |
90 | ······<ocil:actions> | 66 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg-se | 67 | ········<ocil:test_action_ref>ocil:ssg-service_timesyncd_enabled_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 68 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-auditd_ | 70 | ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 71 | ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title> |
96 | ······<ocil:actions> | 72 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg-auditd_ | 73 | ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 74 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg- | 76 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1"> |
101 | ······<ocil:title> | 77 | ······<ocil:title>Enable·automatic·signing·of·all·modules</ocil:title> |
102 | ······<ocil:actions> | 78 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_all_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 80 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg- | 82 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_ocil:questionnaire:1"> |
107 | ······<ocil:title>En | 83 | ······<ocil:title>Enable·different·security·models</ocil:title> |
108 | ······<ocil:actions> | 84 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 86 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg- | 88 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 89 | ······<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title> |
114 | ······<ocil:actions> | 90 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 92 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-a | 94 | ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1"> |
119 | ······<ocil:title> | 95 | ······<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title> |
120 | ······<ocil:actions> | 96 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg-a | 97 | ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 98 | ······</ocil:actions> |
123 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
124 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_list_ocil:questionnaire:1"> |
125 | ······<ocil:title> | 101 | ······<ocil:title>Enable·checks·on·linked·list·manipulation</ocil:title> |
126 | ······<ocil:actions> | 102 | ······<ocil:actions> |
127 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_list_action:testaction:1</ocil:test_action_ref> |
Max diff block lines reached; 666295/677683 bytes (98.32%) of diff not shown. |
Offset 21, 23 lines modified | Offset 21, 23 lines modified | ||
21 | ····<ds:checks> | 21 | ····<ds:checks> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"/> |
24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-cpe-oval.xml"/> | 24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-cpe-oval.xml"/> |
25 | ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.bionic.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.bionic.usn.oval.xml.bz2"/> | 25 | ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.bionic.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.bionic.usn.oval.xml.bz2"/> |
26 | ····</ds:checks> | 26 | ····</ds:checks> |
27 | ··</ds:data-stream> | 27 | ··</ds:data-stream> |
28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-cpe-dictionary.xml"·timestamp="2025-0 | 28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
30 | ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~"> | 30 | ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~"> |
31 | ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·18.04·(Bionic·Beaver)</cpe-dict:title> | 31 | ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·18.04·(Bionic·Beaver)</cpe-dict:title> |
32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1804:def:1</cpe-dict:check> | 32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1804:def:1</cpe-dict:check> |
33 | ······</cpe-dict:cpe-item> | 33 | ······</cpe-dict:cpe-item> |
34 | ····</cpe-dict:cpe-list> | 34 | ····</cpe-dict:cpe-list> |
35 | ··</ds:component> | 35 | ··</ds:component> |
36 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-xccdf.xml"·timestamp="2025-0 | 36 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
37 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 37 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
38 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 38 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
39 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title> | 39 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title> |
40 | ······<xccdf-1.2:description> | 40 | ······<xccdf-1.2:description> |
41 | ········This·guide·presents·a·catalog·of·security-relevant | 41 | ········This·guide·presents·a·catalog·of·security-relevant |
42 | configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of | 42 | configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of |
43 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 43 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 67111, 15 lines modified | Offset 67111, 15 lines modified | ||
67111 | ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1804-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> | 67111 | ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1804-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> |
67112 | ············</xccdf-1.2:check> | 67112 | ············</xccdf-1.2:check> |
67113 | ··········</xccdf-1.2:Rule> | 67113 | ··········</xccdf-1.2:Rule> |
67114 | ········</xccdf-1.2:Group> | 67114 | ········</xccdf-1.2:Group> |
67115 | ······</xccdf-1.2:Group> | 67115 | ······</xccdf-1.2:Group> |
67116 | ····</xccdf-1.2:Benchmark> | 67116 | ····</xccdf-1.2:Benchmark> |
67117 | ··</ds:component> | 67117 | ··</ds:component> |
67118 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"·timestamp="2025-0 | 67118 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"·timestamp="2025-03-01T22:08:00"> |
67119 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 67119 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
67120 | ······<oval-def:generator> | 67120 | ······<oval-def:generator> |
67121 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 67121 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
67122 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 67122 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
67123 | ········<oval:schema_version>5.11</oval:schema_version> | 67123 | ········<oval:schema_version>5.11</oval:schema_version> |
67124 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 67124 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
67125 | ······</oval-def:generator> | 67125 | ······</oval-def:generator> |
Offset 84657, 2958 lines modified | Offset 84657, 2958 lines modified | ||
84657 | ············</oval-def:arithmetic> | 84657 | ············</oval-def:arithmetic> |
84658 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 84658 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
84659 | ··········</oval-def:arithmetic> | 84659 | ··········</oval-def:arithmetic> |
84660 | ········</oval-def:local_variable> | 84660 | ········</oval-def:local_variable> |
84661 | ······</oval-def:variables> | 84661 | ······</oval-def:variables> |
84662 | ····</oval-def:oval_definitions> | 84662 | ····</oval-def:oval_definitions> |
84663 | ··</ds:component> | 84663 | ··</ds:component> |
84664 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"·timestamp="2025-0 | 84664 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
84665 | ····<ocil:ocil> | 84665 | ····<ocil:ocil> |
84666 | ······<ocil:generator> | 84666 | ······<ocil:generator> |
84667 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 84667 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
84668 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 84668 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
84669 | ········<ocil:schema_version>2.0</ocil:schema_version> | 84669 | ········<ocil:schema_version>2.0</ocil:schema_version> |
84670 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 84670 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
84671 | ······</ocil:generator> | 84671 | ······</ocil:generator> |
84672 | ······<ocil:questionnaires> | 84672 | ······<ocil:questionnaires> |
84673 | ········<ocil:questionnaire·id="ocil:ssg-s | 84673 | ········<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1"> |
84674 | ··········<ocil:title> | 84674 | ··········<ocil:title>Enable·systemd-journald·Service</ocil:title> |
84675 | ··········<ocil:actions> | 84675 | ··········<ocil:actions> |
84676 | ············<ocil:test_action_ref>ocil:ssg-s | 84676 | ············<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref> |
84677 | ··········</ocil:actions> | 84677 | ··········</ocil:actions> |
84678 | ········</ocil:questionnaire> | 84678 | ········</ocil:questionnaire> |
84679 | ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1"> | ||
84680 | ········ | 84679 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1"> |
84680 | ··········<ocil:title>Enable·Yama·support</ocil:title> | ||
84681 | ··········<ocil:actions> | 84681 | ··········<ocil:actions> |
84682 | ············<ocil:test_action_ref>ocil:ssg- | 84682 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_security_yama_action:testaction:1</ocil:test_action_ref> |
84683 | ··········</ocil:actions> | 84683 | ··········</ocil:actions> |
84684 | ········</ocil:questionnaire> | 84684 | ········</ocil:questionnaire> |
84685 | ········<ocil:questionnaire·id="ocil:ssg- | 84685 | ········<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nodev_ocil:questionnaire:1"> |
84686 | ··········<ocil:title> | 84686 | ··········<ocil:title>Add·nodev·Option·to·/tmp</ocil:title> |
84687 | ··········<ocil:actions> | 84687 | ··········<ocil:actions> |
84688 | ············<ocil:test_action_ref>ocil:ssg- | 84688 | ············<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nodev_action:testaction:1</ocil:test_action_ref> |
84689 | ··········</ocil:actions> | 84689 | ··········</ocil:actions> |
84690 | ········</ocil:questionnaire> | 84690 | ········</ocil:questionnaire> |
84691 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_ | 84691 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1"> |
84692 | ··········<ocil:title>Verify·User·Who·Owns·/var/log/ | 84692 | ··········<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title> |
84693 | ··········<ocil:actions> | 84693 | ··········<ocil:actions> |
84694 | ············<ocil:test_action_ref>ocil:ssg-file_owner_var_log_ | 84694 | ············<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref> |
84695 | ··········</ocil:actions> | 84695 | ··········</ocil:actions> |
84696 | ········</ocil:questionnaire> | 84696 | ········</ocil:questionnaire> |
84697 | ········<ocil:questionnaire·id="ocil:ssg- | 84697 | ········<ocil:questionnaire·id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1"> |
84698 | ··········<ocil:title> | 84698 | ··········<ocil:title>Prefer·to·use·a·64-bit·Operating·System·when·supported</ocil:title> |
84699 | ··········<ocil:actions> | 84699 | ··········<ocil:actions> |
84700 | ············<ocil:test_action_ref>ocil:ssg- | 84700 | ············<ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref> |
84701 | ··········</ocil:actions> | 84701 | ··········</ocil:actions> |
84702 | ········</ocil:questionnaire> | 84702 | ········</ocil:questionnaire> |
84703 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1"> | ||
84704 | ········ | 84703 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_ocil:questionnaire:1"> |
84704 | ··········<ocil:title>Record·Events·that·Modify·User/Group·Information</ocil:title> | ||
84705 | ··········<ocil:actions> | 84705 | ··········<ocil:actions> |
84706 | ············<ocil:test_action_ref>ocil:ssg- | 84706 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_action:testaction:1</ocil:test_action_ref> |
84707 | ··········</ocil:actions> | 84707 | ··········</ocil:actions> |
84708 | ········</ocil:questionnaire> | 84708 | ········</ocil:questionnaire> |
84709 | ········<ocil:questionnaire·id="ocil:ssg- | 84709 | ········<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1"> |
84710 | ··········<ocil:title> | 84710 | ··········<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title> |
84711 | ··········<ocil:actions> | 84711 | ··········<ocil:actions> |
84712 | ············<ocil:test_action_ref>ocil:ssg- | 84712 | ············<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref> |
84713 | ··········</ocil:actions> | 84713 | ··········</ocil:actions> |
84714 | ········</ocil:questionnaire> | 84714 | ········</ocil:questionnaire> |
84715 | ········<ocil:questionnaire·id="ocil:ssg- | 84715 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1"> |
84716 | ··········<ocil:title> | 84716 | ··········<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title> |
84717 | ··········<ocil:actions> | 84717 | ··········<ocil:actions> |
84718 | ············<ocil:test_action_ref>ocil:ssg- | 84718 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref> |
84719 | ··········</ocil:actions> | 84719 | ··········</ocil:actions> |
84720 | ········</ocil:questionnaire> | 84720 | ········</ocil:questionnaire> |
84721 | ········<ocil:questionnaire·id="ocil:ssg-a | 84721 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> |
84722 | ··········<ocil:title> | 84722 | ··········<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title> |
84723 | ··········<ocil:actions> | 84723 | ··········<ocil:actions> |
84724 | ············<ocil:test_action_ref>ocil:ssg-a | 84724 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref> |
84725 | ··········</ocil:actions> | 84725 | ··········</ocil:actions> |
84726 | ········</ocil:questionnaire> | 84726 | ········</ocil:questionnaire> |
84727 | ········<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_pub_key_ocil:questionnaire:1"> | ||
84728 | ········ | 84727 | ········<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1"> |
84728 | ··········<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title> | ||
84729 | ··········<ocil:actions> | 84729 | ··········<ocil:actions> |
84730 | ············<ocil:test_action_ref>ocil:ssg- | 84730 | ············<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref> |
84731 | ··········</ocil:actions> | 84731 | ··········</ocil:actions> |
84732 | ········</ocil:questionnaire> | 84732 | ········</ocil:questionnaire> |
84733 | ········<ocil:questionnaire·id="ocil:ssg- | 84733 | ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1"> |
84734 | ··········<ocil:title>Configure· | 84734 | ··········<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title> |
84735 | ··········<ocil:actions> | 84735 | ··········<ocil:actions> |
84736 | ············<ocil:test_action_ref>ocil:ssg- | 84736 | ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref> |
84737 | ··········</ocil:actions> | 84737 | ··········</ocil:actions> |
84738 | ········</ocil:questionnaire> | 84738 | ········</ocil:questionnaire> |
84739 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_ | 84739 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1"> |
84740 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-· | 84740 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title> |
Max diff block lines reached; 729696/742017 bytes (98.34%) of diff not shown. |
Offset 3, 2949 lines modified | Offset 3, 2949 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-s | 10 | ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1"> |
11 | ······<ocil:title> | 11 | ······<ocil:title>Enable·systemd-journald·Service</ocil:title> |
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg-s | 13 | ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1"> | ||
17 | ···· | 16 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1"> |
17 | ······<ocil:title>Enable·Yama·support</ocil:title> | ||
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_yama_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nodev_ocil:questionnaire:1"> |
23 | ······<ocil:title> | 23 | ······<ocil:title>Add·nodev·Option·to·/tmp</ocil:title> |
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nodev_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_ | 28 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1"> |
29 | ······<ocil:title>Verify·User·Who·Owns·/var/log/ | 29 | ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title> |
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_ | 31 | ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1"> |
35 | ······<ocil:title> | 35 | ······<ocil:title>Prefer·to·use·a·64-bit·Operating·System·when·supported</ocil:title> |
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1"> | ||
41 | ···· | 40 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_ocil:questionnaire:1"> |
41 | ······<ocil:title>Record·Events·that·Modify·User/Group·Information</ocil:title> | ||
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1"> | ||
47 | ···· | 46 | ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1"> |
47 | ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title> | ||
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 52 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 53 | ······<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title> |
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-a | 58 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 59 | ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title> |
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg-a | 61 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_pub_key_ocil:questionnaire:1"> | ||
65 | ···· | 64 | ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1"> |
65 | ······<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title> | ||
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_relayhost_ocil:questionnaire:1"> | ||
71 | ···· | 70 | ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1"> |
71 | ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title> | ||
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_ | 76 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1"> |
77 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-· | 77 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title> |
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_ | 79 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg- | 82 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_sha512_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 83 | ······<ocil:title>Sign·kernel·modules·with·SHA-512</ocil:title> |
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_sha512_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg- | 88 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_proc_kcore_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 89 | ······<ocil:title>Disable·support·for·/proc/kkcore</ocil:title> |
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_proc_kcore_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-a | 94 | ····<ocil:questionnaire·id="ocil:ssg-aide_disable_silentreports_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 95 | ······<ocil:title>Configure·AIDE·To·Notify·Personnel·if·Baseline·Configurations·Are·Altered</ocil:title> |
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg-a | 97 | ········<ocil:test_action_ref>ocil:ssg-aide_disable_silentreports_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-auditd_log_format_ocil:questionnaire:1"> |
101 | ······<ocil:title> | 101 | ······<ocil:title>Resolve·information·before·writing·to·audit·logs</ocil:title> |
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-auditd_log_format_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg- | 106 | ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 107 | ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title> |
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg- | 112 | ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_stig_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 113 | ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title> |
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_stig_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg- | 118 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1"> |
119 | ······<ocil:title> | 119 | ······<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title> |
120 | ······<ocil:actions> | 120 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg- | 121 | ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 122 | ······</ocil:actions> |
123 | ····</ocil:questionnaire> | 123 | ····</ocil:questionnaire> |
124 | ····<ocil:questionnaire·id="ocil:ssg- | 124 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_gshadow_ocil:questionnaire:1"> |
Max diff block lines reached; 693264/705909 bytes (98.21%) of diff not shown. |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·20.04·(Focal·Fossa)</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·20.04·(Focal·Fossa)</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2004:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2004:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of | 40 | configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 143123, 15 lines modified | Offset 143123, 15 lines modified | ||
143123 | ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2004-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/> | 143123 | ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2004-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/> |
143124 | ············</xccdf-1.2:check> | 143124 | ············</xccdf-1.2:check> |
143125 | ··········</xccdf-1.2:Rule> | 143125 | ··········</xccdf-1.2:Rule> |
143126 | ········</xccdf-1.2:Group> | 143126 | ········</xccdf-1.2:Group> |
143127 | ······</xccdf-1.2:Group> | 143127 | ······</xccdf-1.2:Group> |
143128 | ····</xccdf-1.2:Benchmark> | 143128 | ····</xccdf-1.2:Benchmark> |
143129 | ··</ds:component> | 143129 | ··</ds:component> |
143130 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"·timestamp="2025-0 | 143130 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"·timestamp="2025-03-01T22:08:00"> |
143131 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 143131 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
143132 | ······<oval-def:generator> | 143132 | ······<oval-def:generator> |
143133 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 143133 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
143134 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 143134 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
143135 | ········<oval:schema_version>5.11</oval:schema_version> | 143135 | ········<oval:schema_version>5.11</oval:schema_version> |
143136 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 143136 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
143137 | ······</oval-def:generator> | 143137 | ······</oval-def:generator> |
Offset 174684, 8954 lines modified | Offset 174684, 8907 lines modified | ||
174684 | ············</oval-def:arithmetic> | 174684 | ············</oval-def:arithmetic> |
174685 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 174685 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
174686 | ··········</oval-def:arithmetic> | 174686 | ··········</oval-def:arithmetic> |
174687 | ········</oval-def:local_variable> | 174687 | ········</oval-def:local_variable> |
174688 | ······</oval-def:variables> | 174688 | ······</oval-def:variables> |
174689 | ····</oval-def:oval_definitions> | 174689 | ····</oval-def:oval_definitions> |
174690 | ··</ds:component> | 174690 | ··</ds:component> |
174691 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"·timestamp="2025-0 | 174691 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
174692 | ····<ocil:ocil> | 174692 | ····<ocil:ocil> |
174693 | ······<ocil:generator> | 174693 | ······<ocil:generator> |
174694 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 174694 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
174695 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 174695 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
174696 | ········<ocil:schema_version>2.0</ocil:schema_version> | 174696 | ········<ocil:schema_version>2.0</ocil:schema_version> |
174697 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 174697 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
174698 | ······</ocil:generator> | 174698 | ······</ocil:generator> |
174699 | ······<ocil:questionnaires> | 174699 | ······<ocil:questionnaires> |
174700 | ········<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1"> | ||
174701 | ········ | 174700 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1"> |
174701 | ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title> | ||
174702 | ··········<ocil:actions> | 174702 | ··········<ocil:actions> |
174703 | ············<ocil:test_action_ref>ocil:ssg- | 174703 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref> |
174704 | ··········</ocil:actions> | 174704 | ··········</ocil:actions> |
174705 | ········</ocil:questionnaire> | 174705 | ········</ocil:questionnaire> |
174706 | ········<ocil:questionnaire·id="ocil:ssg- | 174706 | ········<ocil:questionnaire·id="ocil:ssg-package_iptables-persistent_removed_ocil:questionnaire:1"> |
174707 | ··········<ocil:title>Remove· | 174707 | ··········<ocil:title>Remove·iptables-persistent·Package</ocil:title> |
174708 | ··········<ocil:actions> | 174708 | ··········<ocil:actions> |
174709 | ············<ocil:test_action_ref>ocil:ssg- | 174709 | ············<ocil:test_action_ref>ocil:ssg-package_iptables-persistent_removed_action:testaction:1</ocil:test_action_ref> |
174710 | ··········</ocil:actions> | 174710 | ··········</ocil:actions> |
174711 | ········</ocil:questionnaire> | 174711 | ········</ocil:questionnaire> |
174712 | ········<ocil:questionnaire·id="ocil:ssg- | 174712 | ········<ocil:questionnaire·id="ocil:ssg-coredump_disable_storage_ocil:questionnaire:1"> |
174713 | ··········<ocil:title> | 174713 | ··········<ocil:title>Disable·storing·core·dump</ocil:title> |
174714 | ··········<ocil:actions> | 174714 | ··········<ocil:actions> |
174715 | ············<ocil:test_action_ref>ocil:ssg- | 174715 | ············<ocil:test_action_ref>ocil:ssg-coredump_disable_storage_action:testaction:1</ocil:test_action_ref> |
174716 | ··········</ocil:actions> | 174716 | ··········</ocil:actions> |
174717 | ········</ocil:questionnaire> | 174717 | ········</ocil:questionnaire> |
174718 | ········<ocil:questionnaire·id="ocil:ssg-s | 174718 | ········<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1"> |
174719 | ··········<ocil:title> | 174719 | ··········<ocil:title>Verify·iptables·Enabled</ocil:title> |
174720 | ··········<ocil:actions> | 174720 | ··········<ocil:actions> |
174721 | ············<ocil:test_action_ref>ocil:ssg-s | 174721 | ············<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref> |
174722 | ··········</ocil:actions> | 174722 | ··········</ocil:actions> |
174723 | ········</ocil:questionnaire> | 174723 | ········</ocil:questionnaire> |
174724 | ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1"> | ||
174725 | ········ | 174724 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1"> |
174725 | ··········<ocil:title>Randomize·the·kernel·memory·sections</ocil:title> | ||
174726 | ··········<ocil:actions> | 174726 | ··········<ocil:actions> |
174727 | ············<ocil:test_action_ref>ocil:ssg- | 174727 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref> |
174728 | ··········</ocil:actions> | 174728 | ··········</ocil:actions> |
174729 | ········</ocil:questionnaire> | 174729 | ········</ocil:questionnaire> |
174730 | ········<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1"> | ||
174731 | ········ | 174730 | ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_banner_enabled_ocil:questionnaire:1"> |
174731 | ··········<ocil:title>Enable·GNOME3·Login·Warning·Banner</ocil:title> | ||
174732 | ··········<ocil:actions> | 174732 | ··········<ocil:actions> |
174733 | ············<ocil:test_action_ref>ocil:ssg- | 174733 | ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_banner_enabled_action:testaction:1</ocil:test_action_ref> |
174734 | ··········</ocil:actions> | 174734 | ··········</ocil:actions> |
174735 | ········</ocil:questionnaire> | 174735 | ········</ocil:questionnaire> |
174736 | ········<ocil:questionnaire·id="ocil:ssg-s | 174736 | ········<ocil:questionnaire·id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1"> |
174737 | ··········<ocil:title> | 174737 | ··········<ocil:title>Ensure·all·users·last·password·change·date·is·in·the·past</ocil:title> |
174738 | ··········<ocil:actions> | 174738 | ··········<ocil:actions> |
174739 | ············<ocil:test_action_ref>ocil:ssg-s | 174739 | ············<ocil:test_action_ref>ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1</ocil:test_action_ref> |
174740 | ··········</ocil:actions> | 174740 | ··········</ocil:actions> |
174741 | ········</ocil:questionnaire> | 174741 | ········</ocil:questionnaire> |
174742 | ········<ocil:questionnaire·id="ocil:ssg- | 174742 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_ocil:questionnaire:1"> |
174743 | ··········<ocil:title>Disable·C | 174743 | ··········<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv6·Interfaces</ocil:title> |
174744 | ··········<ocil:actions> | 174744 | ··········<ocil:actions> |
174745 | ············<ocil:test_action_ref>ocil:ssg- | 174745 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref> |
174746 | ··········</ocil:actions> | 174746 | ··········</ocil:actions> |
174747 | ········</ocil:questionnaire> | 174747 | ········</ocil:questionnaire> |
174748 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_ | 174748 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_ocil:questionnaire:1"> |
174749 | ··········<ocil:title> | 174749 | ··········<ocil:title>Disable·Accepting·Packets·Routed·Between·Local·Interfaces</ocil:title> |
174750 | ··········<ocil:actions> | 174750 | ··········<ocil:actions> |
174751 | ············<ocil:test_action_ref>ocil:ssg-sysctl_ | 174751 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_action:testaction:1</ocil:test_action_ref> |
174752 | ··········</ocil:actions> | 174752 | ··········</ocil:actions> |
174753 | ········</ocil:questionnaire> | 174753 | ········</ocil:questionnaire> |
174754 | ········<ocil:questionnaire·id="ocil:ssg- | 174754 | ········<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1"> |
174755 | ··········<ocil:title> | 174755 | ··········<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title> |
174756 | ··········<ocil:actions> | 174756 | ··········<ocil:actions> |
174757 | ············<ocil:test_action_ref>ocil:ssg- | 174757 | ············<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref> |
174758 | ··········</ocil:actions> | 174758 | ··········</ocil:actions> |
174759 | ········</ocil:questionnaire> | 174759 | ········</ocil:questionnaire> |
174760 | ········<ocil:questionnaire·id="ocil:ssg- | 174760 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1"> |
174761 | ··········<ocil:title> | 174761 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title> |
174762 | ··········<ocil:actions> | 174762 | ··········<ocil:actions> |
174763 | ············<ocil:test_action_ref>ocil:ssg- | 174763 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref> |
174764 | ··········</ocil:actions> | 174764 | ··········</ocil:actions> |
174765 | ········</ocil:questionnaire> | 174765 | ········</ocil:questionnaire> |
174766 | ········<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1"> | ||
174767 | ········ | 174766 | ········<ocil:questionnaire·id="ocil:ssg-no_direct_root_logins_ocil:questionnaire:1"> |
Max diff block lines reached; 1417606/1429833 bytes (99.14%) of diff not shown. |
Offset 3, 8945 lines modified | Offset 3, 8898 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1"> | ||
11 | ···· | 10 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1"> |
11 | ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title> | ||
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg- | 16 | ····<ocil:questionnaire·id="ocil:ssg-package_iptables-persistent_removed_ocil:questionnaire:1"> |
17 | ······<ocil:title>Remove· | 17 | ······<ocil:title>Remove·iptables-persistent·Package</ocil:title> |
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-package_iptables-persistent_removed_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-coredump_disable_storage_ocil:questionnaire:1"> |
23 | ······<ocil:title> | 23 | ······<ocil:title>Disable·storing·core·dump</ocil:title> |
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-coredump_disable_storage_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-s | 28 | ····<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1"> |
29 | ······<ocil:title> | 29 | ······<ocil:title>Verify·iptables·Enabled</ocil:title> |
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg-s | 31 | ········<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1"> | ||
35 | ···· | 34 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1"> |
35 | ······<ocil:title>Randomize·the·kernel·memory·sections</ocil:title> | ||
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1"> | ||
41 | ···· | 40 | ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_banner_enabled_ocil:questionnaire:1"> |
41 | ······<ocil:title>Enable·GNOME3·Login·Warning·Banner</ocil:title> | ||
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_banner_enabled_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-s | 46 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1"> |
47 | ······<ocil:title> | 47 | ······<ocil:title>Ensure·all·users·last·password·change·date·is·in·the·past</ocil:title> |
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg-s | 49 | ········<ocil:test_action_ref>ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1"> | ||
53 | ···· | 52 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_ocil:questionnaire:1"> |
53 | ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv6·Interfaces</ocil:title> | ||
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_ | 58 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 59 | ······<ocil:title>Disable·Accepting·Packets·Routed·Between·Local·Interfaces</ocil:title> |
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg-sysctl_ | 61 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1"> |
65 | ······<ocil:title> | 65 | ······<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title> |
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 71 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title> |
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1"> | ||
77 | ···· | 76 | ····<ocil:questionnaire·id="ocil:ssg-no_direct_root_logins_ocil:questionnaire:1"> |
77 | ······<ocil:title>Direct·root·Logins·Not·Allowed</ocil:title> | ||
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-no_direct_root_logins_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-pa | 82 | ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 83 | ······<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title> |
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg-pa | 85 | ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmodat_ocil:questionnaire:1"> | ||
89 | ···· | 88 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_shadow_ocil:questionnaire:1"> |
89 | ······<ocil:title>Verify·User·Who·Owns·Backup·shadow·File</ocil:title> | ||
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg- | 94 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_nodev_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 95 | ······<ocil:title>Add·nodev·Option·to·/var/tmp</ocil:title> |
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_nodev_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_session_events_wtmp_ocil:questionnaire:1"> |
101 | ······<ocil:title> | 101 | ······<ocil:title>Record·Attempts·to·Alter·Process·and·Session·Initiation·Information·wtmp</ocil:title> |
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_session_events_wtmp_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-dir_perms_world_writable_sticky_bits_ocil:questionnaire:1"> | ||
107 | ···· | 106 | ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1"> |
107 | ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title> | ||
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ssh_keysign_ocil:questionnaire:1"> | ||
113 | ···· | 112 | ····<ocil:questionnaire·id="ocil:ssg-zipl_audit_backlog_limit_argument_ocil:questionnaire:1"> |
113 | ······<ocil:title>Extend·Audit·Backlog·Limit·for·the·Audit·Daemon·in·zIPL</ocil:title> | ||
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-zipl_audit_backlog_limit_argument_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1"> | ||
119 | ···· | 118 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1"> |
119 | ······<ocil:title>Verify·Permissions·on·/etc/cron.allow·file</ocil:title> | ||
120 | ······<ocil:actions> | 120 | ······<ocil:actions> |
Max diff block lines reached; 1353920/1366580 bytes (99.07%) of diff not shown. |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·22.04·(Jammy·Jellyfish)</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·22.04·(Jammy·Jellyfish)</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2204:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2204:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of | 40 | configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 148842, 15 lines modified | Offset 148842, 15 lines modified | ||
148842 | ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2204-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/> | 148842 | ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2204-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/> |
148843 | ············</xccdf-1.2:check> | 148843 | ············</xccdf-1.2:check> |
148844 | ··········</xccdf-1.2:Rule> | 148844 | ··········</xccdf-1.2:Rule> |
148845 | ········</xccdf-1.2:Group> | 148845 | ········</xccdf-1.2:Group> |
148846 | ······</xccdf-1.2:Group> | 148846 | ······</xccdf-1.2:Group> |
148847 | ····</xccdf-1.2:Benchmark> | 148847 | ····</xccdf-1.2:Benchmark> |
148848 | ··</ds:component> | 148848 | ··</ds:component> |
148849 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"·timestamp="2025-0 | 148849 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"·timestamp="2025-03-01T22:08:00"> |
148850 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 148850 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
148851 | ······<oval-def:generator> | 148851 | ······<oval-def:generator> |
148852 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 148852 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
148853 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 148853 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
148854 | ········<oval:schema_version>5.11</oval:schema_version> | 148854 | ········<oval:schema_version>5.11</oval:schema_version> |
148855 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 148855 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
148856 | ······</oval-def:generator> | 148856 | ······</oval-def:generator> |
Offset 181748, 7513 lines modified | Offset 181748, 7513 lines modified | ||
181748 | ············</oval-def:arithmetic> | 181748 | ············</oval-def:arithmetic> |
181749 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 181749 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
181750 | ··········</oval-def:arithmetic> | 181750 | ··········</oval-def:arithmetic> |
181751 | ········</oval-def:local_variable> | 181751 | ········</oval-def:local_variable> |
181752 | ······</oval-def:variables> | 181752 | ······</oval-def:variables> |
181753 | ····</oval-def:oval_definitions> | 181753 | ····</oval-def:oval_definitions> |
181754 | ··</ds:component> | 181754 | ··</ds:component> |
181755 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"·timestamp="2025-0 | 181755 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
181756 | ····<ocil:ocil> | 181756 | ····<ocil:ocil> |
181757 | ······<ocil:generator> | 181757 | ······<ocil:generator> |
181758 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 181758 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
181759 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 181759 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
181760 | ········<ocil:schema_version>2.0</ocil:schema_version> | 181760 | ········<ocil:schema_version>2.0</ocil:schema_version> |
181761 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 181761 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
181762 | ······</ocil:generator> | 181762 | ······</ocil:generator> |
181763 | ······<ocil:questionnaires> | 181763 | ······<ocil:questionnaires> |
181764 | ········<ocil:questionnaire·id="ocil:ssg- | 181764 | ········<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1"> |
181765 | ··········<ocil:title> | 181765 | ··········<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title> |
181766 | ··········<ocil:actions> | 181766 | ··········<ocil:actions> |
181767 | ············<ocil:test_action_ref>ocil:ssg- | 181767 | ············<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref> |
181768 | ··········</ocil:actions> | 181768 | ··········</ocil:actions> |
181769 | ········</ocil:questionnaire> | 181769 | ········</ocil:questionnaire> |
181770 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"> | ||
181771 | ········ | 181770 | ········<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1"> |
181771 | ··········<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title> | ||
181772 | ··········<ocil:actions> | 181772 | ··········<ocil:actions> |
181773 | ············<ocil:test_action_ref>ocil:ssg- | 181773 | ············<ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref> |
181774 | ··········</ocil:actions> | 181774 | ··········</ocil:actions> |
181775 | ········</ocil:questionnaire> | 181775 | ········</ocil:questionnaire> |
181776 | ········<ocil:questionnaire·id="ocil:ssg- | 181776 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1"> |
181777 | ··········<ocil:title>Enable· | 181777 | ··········<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title> |
181778 | ··········<ocil:actions> | 181778 | ··········<ocil:actions> |
181779 | ············<ocil:test_action_ref>ocil:ssg- | 181779 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref> |
181780 | ··········</ocil:actions> | 181780 | ··········</ocil:actions> |
181781 | ········</ocil:questionnaire> | 181781 | ········</ocil:questionnaire> |
181782 | ········<ocil:questionnaire·id="ocil:ssg-ss | 181782 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1"> |
181783 | ··········<ocil:title> | 181783 | ··········<ocil:title>Disable·Accepting·Router·Advertisements·on·all·IPv6·Interfaces·by·Default</ocil:title> |
181784 | ··········<ocil:actions> | 181784 | ··········<ocil:actions> |
181785 | ············<ocil:test_action_ref>ocil:ssg-ss | 181785 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1</ocil:test_action_ref> |
181786 | ··········</ocil:actions> | 181786 | ··········</ocil:actions> |
181787 | ········</ocil:questionnaire> | 181787 | ········</ocil:questionnaire> |
181788 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_sudoers_d_ocil:questionnaire:1"> | ||
181789 | ········ | 181788 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1"> |
181789 | ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title> | ||
181790 | ··········<ocil:actions> | 181790 | ··········<ocil:actions> |
181791 | ············<ocil:test_action_ref>ocil:ssg- | 181791 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref> |
181792 | ··········</ocil:actions> | 181792 | ··········</ocil:actions> |
181793 | ········</ocil:questionnaire> | 181793 | ········</ocil:questionnaire> |
181794 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_ | 181794 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1"> |
181795 | ··········<ocil:title> | 181795 | ··········<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title> |
181796 | ··········<ocil:actions> | 181796 | ··········<ocil:actions> |
181797 | ············<ocil:test_action_ref>ocil:ssg-sysctl_ | 181797 | ············<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref> |
181798 | ··········</ocil:actions> | 181798 | ··········</ocil:actions> |
181799 | ········</ocil:questionnaire> | 181799 | ········</ocil:questionnaire> |
181800 | ········<ocil:questionnaire·id="ocil:ssg-a | 181800 | ········<ocil:questionnaire·id="ocil:ssg-smartcard_configure_cert_checking_ocil:questionnaire:1"> |
181801 | ··········<ocil:title> | 181801 | ··········<ocil:title>Configure·Smart·Card·Certificate·Status·Checking</ocil:title> |
181802 | ··········<ocil:actions> | 181802 | ··········<ocil:actions> |
181803 | ············<ocil:test_action_ref>ocil:ssg-a | 181803 | ············<ocil:test_action_ref>ocil:ssg-smartcard_configure_cert_checking_action:testaction:1</ocil:test_action_ref> |
181804 | ··········</ocil:actions> | 181804 | ··········</ocil:actions> |
181805 | ········</ocil:questionnaire> | 181805 | ········</ocil:questionnaire> |
181806 | ········<ocil:questionnaire·id="ocil:ssg- | 181806 | ········<ocil:questionnaire·id="ocil:ssg-vlock_installed_ocil:questionnaire:1"> |
181807 | ··········<ocil:title> | 181807 | ··········<ocil:title>Check·that·vlock·is·installed·to·allow·session·locking</ocil:title> |
181808 | ··········<ocil:actions> | 181808 | ··········<ocil:actions> |
181809 | ············<ocil:test_action_ref>ocil:ssg- | 181809 | ············<ocil:test_action_ref>ocil:ssg-vlock_installed_action:testaction:1</ocil:test_action_ref> |
181810 | ··········</ocil:actions> | 181810 | ··········</ocil:actions> |
181811 | ········</ocil:questionnaire> | 181811 | ········</ocil:questionnaire> |
181812 | ········<ocil:questionnaire·id="ocil:ssg- | 181812 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_symlinks_ocil:questionnaire:1"> |
181813 | ··········<ocil:title> | 181813 | ··········<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Symlinks</ocil:title> |
181814 | ··········<ocil:actions> | 181814 | ··········<ocil:actions> |
181815 | ············<ocil:test_action_ref>ocil:ssg- | 181815 | ············<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_symlinks_action:testaction:1</ocil:test_action_ref> |
181816 | ··········</ocil:actions> | 181816 | ··········</ocil:actions> |
181817 | ········</ocil:questionnaire> | 181817 | ········</ocil:questionnaire> |
181818 | ········<ocil:questionnaire·id="ocil:ssg- | 181818 | ········<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1"> |
181819 | ··········<ocil:title> | 181819 | ··········<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title> |
181820 | ··········<ocil:actions> | 181820 | ··········<ocil:actions> |
181821 | ············<ocil:test_action_ref>ocil:ssg- | 181821 | ············<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref> |
181822 | ··········</ocil:actions> | 181822 | ··········</ocil:actions> |
181823 | ········</ocil:questionnaire> | 181823 | ········</ocil:questionnaire> |
181824 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_ | 181824 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1"> |
181825 | ··········<ocil:title> | 181825 | ··········<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title> |
181826 | ··········<ocil:actions> | 181826 | ··········<ocil:actions> |
181827 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_ | 181827 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref> |
181828 | ··········</ocil:actions> | 181828 | ··········</ocil:actions> |
181829 | ········</ocil:questionnaire> | 181829 | ········</ocil:questionnaire> |
181830 | ········<ocil:questionnaire·id="ocil:ssg-a | 181830 | ········<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1"> |
181831 | ··········<ocil:title> | 181831 | ··········<ocil:title>Ensure·LDAP·client·is·not·installed</ocil:title> |
181832 | ··········<ocil:actions> | 181832 | ··········<ocil:actions> |
Max diff block lines reached; 1482255/1495028 bytes (99.15%) of diff not shown. |
Offset 3, 7504 lines modified | Offset 3, 7504 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg- | 10 | ····<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1"> |
11 | ······<ocil:title> | 11 | ······<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title> |
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"> | ||
17 | ···· | 16 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1"> |
17 | ······<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title> | ||
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1"> |
23 | ······<ocil:title>Enable· | 23 | ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title> |
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-ss | 28 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1"> |
29 | ······<ocil:title> | 29 | ······<ocil:title>Disable·Accepting·Router·Advertisements·on·all·IPv6·Interfaces·by·Default</ocil:title> |
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg-ss | 31 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sudoers_d_ocil:questionnaire:1"> | ||
35 | ···· | 34 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1"> |
35 | ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title> | ||
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_ocil:questionnaire:1"> | ||
41 | ···· | 40 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1"> |
41 | ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title> | ||
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg-sysctl_ | 43 | ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-a | 46 | ····<ocil:questionnaire·id="ocil:ssg-smartcard_configure_cert_checking_ocil:questionnaire:1"> |
47 | ······<ocil:title> | 47 | ······<ocil:title>Configure·Smart·Card·Certificate·Status·Checking</ocil:title> |
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg-a | 49 | ········<ocil:test_action_ref>ocil:ssg-smartcard_configure_cert_checking_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 52 | ····<ocil:questionnaire·id="ocil:ssg-vlock_installed_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 53 | ······<ocil:title>Check·that·vlock·is·installed·to·allow·session·locking</ocil:title> |
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-vlock_installed_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_symlinks_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 59 | ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Symlinks</ocil:title> |
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_symlinks_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1"> |
65 | ······<ocil:title> | 65 | ······<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title> |
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ | 70 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 71 | ······<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title> |
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_ | 73 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1"> | ||
77 | ···· | 76 | ····<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1"> |
77 | ······<ocil:title>Ensure·LDAP·client·is·not·installed</ocil:title> | ||
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg-a | 79 | ········<ocil:test_action_ref>ocil:ssg-package_openldap-clients_removed_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg- | 82 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_hibernation_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 83 | ······<ocil:title>Disable·hibernation</ocil:title> |
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_hibernation_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_shadow_ocil:questionnaire:1"> | ||
89 | ···· | 88 | ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1"> |
89 | ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title> | ||
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1"> | ||
95 | ···· | 94 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1"> |
95 | ······<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title> | ||
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1"> | ||
101 | ···· | 100 | ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1"> |
101 | ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title> | ||
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg- | 106 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 107 | ······<ocil:title>Record·Any·Attempts·to·Run·chcon</ocil:title> |
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg- | 112 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_sudoedit_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 113 | ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·sudoedit</ocil:title> |
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_sudoedit_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-ss | 118 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"> |
119 | ······<ocil:title> | 119 | ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title> |
120 | ······<ocil:actions> | 120 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg-ss | 121 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 122 | ······</ocil:actions> |
Max diff block lines reached; 1416441/1429334 bytes (99.10%) of diff not shown. |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:24.04::~~lts~~~"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:24.04::~~lts~~~"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·24.04·(Noble·Numbat)</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·24.04·(Noble·Numbat)</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2404:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2404:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_24-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_24-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·24.04</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·24.04</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Ubuntu·24.04.·It·is·a·rendering·of | 40 | configuration·settings·for·Ubuntu·24.04.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 102298, 15 lines modified | Offset 102298, 15 lines modified | ||
102298 | ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2404-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/> | 102298 | ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2404-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/> |
102299 | ············</xccdf-1.2:check> | 102299 | ············</xccdf-1.2:check> |
102300 | ··········</xccdf-1.2:Rule> | 102300 | ··········</xccdf-1.2:Rule> |
102301 | ········</xccdf-1.2:Group> | 102301 | ········</xccdf-1.2:Group> |
102302 | ······</xccdf-1.2:Group> | 102302 | ······</xccdf-1.2:Group> |
102303 | ····</xccdf-1.2:Benchmark> | 102303 | ····</xccdf-1.2:Benchmark> |
102304 | ··</ds:component> | 102304 | ··</ds:component> |
102305 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"·timestamp="2025-0 | 102305 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"·timestamp="2025-03-01T22:08:00"> |
102306 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 102306 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
102307 | ······<oval-def:generator> | 102307 | ······<oval-def:generator> |
102308 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 102308 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
102309 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 102309 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
102310 | ········<oval:schema_version>5.11</oval:schema_version> | 102310 | ········<oval:schema_version>5.11</oval:schema_version> |
102311 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 102311 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
102312 | ······</oval-def:generator> | 102312 | ······</oval-def:generator> |
Offset 123597, 3952 lines modified | Offset 123597, 3952 lines modified | ||
123597 | ············</oval-def:arithmetic> | 123597 | ············</oval-def:arithmetic> |
123598 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 123598 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
123599 | ··········</oval-def:arithmetic> | 123599 | ··········</oval-def:arithmetic> |
123600 | ········</oval-def:local_variable> | 123600 | ········</oval-def:local_variable> |
123601 | ······</oval-def:variables> | 123601 | ······</oval-def:variables> |
123602 | ····</oval-def:oval_definitions> | 123602 | ····</oval-def:oval_definitions> |
123603 | ··</ds:component> | 123603 | ··</ds:component> |
123604 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"·timestamp="2025-0 | 123604 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
123605 | ····<ocil:ocil> | 123605 | ····<ocil:ocil> |
123606 | ······<ocil:generator> | 123606 | ······<ocil:generator> |
123607 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 123607 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
123608 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 123608 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
123609 | ········<ocil:schema_version>2.0</ocil:schema_version> | 123609 | ········<ocil:schema_version>2.0</ocil:schema_version> |
123610 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 123610 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
123611 | ······</ocil:generator> | 123611 | ······</ocil:generator> |
123612 | ······<ocil:questionnaires> | 123612 | ······<ocil:questionnaires> |
123613 | ········<ocil:questionnaire·id="ocil:ssg- | 123613 | ········<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_info_ocil:questionnaire:1"> |
123614 | ··········<ocil:title> | 123614 | ··········<ocil:title>Set·LogLevel·to·INFO</ocil:title> |
123615 | ··········<ocil:actions> | 123615 | ··········<ocil:actions> |
123616 | ············<ocil:test_action_ref>ocil:ssg- | 123616 | ············<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_info_action:testaction:1</ocil:test_action_ref> |
123617 | ··········</ocil:actions> | 123617 | ··········</ocil:actions> |
123618 | ········</ocil:questionnaire> | 123618 | ········</ocil:questionnaire> |
123619 | ········<ocil:questionnaire·id="ocil:ssg- | 123619 | ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_audit_nosuid_ocil:questionnaire:1"> |
123620 | ··········<ocil:title> | 123620 | ··········<ocil:title>Add·nosuid·Option·to·/var/log/audit</ocil:title> |
123621 | ··········<ocil:actions> | 123621 | ··········<ocil:actions> |
123622 | ············<ocil:test_action_ref>ocil:ssg- | 123622 | ············<ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_nosuid_action:testaction:1</ocil:test_action_ref> |
123623 | ··········</ocil:actions> | 123623 | ··········</ocil:actions> |
123624 | ········</ocil:questionnaire> | 123624 | ········</ocil:questionnaire> |
123625 | ········<ocil:questionnaire·id="ocil:ssg- | 123625 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1"> |
123626 | ··········<ocil:title> | 123626 | ··········<ocil:title>Verify·Owner·on·crontab</ocil:title> |
123627 | ··········<ocil:actions> | 123627 | ··········<ocil:actions> |
123628 | ············<ocil:test_action_ref>ocil:ssg- | 123628 | ············<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref> |
123629 | ··········</ocil:actions> | 123629 | ··········</ocil:actions> |
123630 | ········</ocil:questionnaire> | 123630 | ········</ocil:questionnaire> |
123631 | ········<ocil:questionnaire·id="ocil:ssg- | 123631 | ········<ocil:questionnaire·id="ocil:ssg-package_rsh_removed_ocil:questionnaire:1"> |
123632 | ··········<ocil:title> | 123632 | ··········<ocil:title>Uninstall·rsh·Package</ocil:title> |
123633 | ··········<ocil:actions> | 123633 | ··········<ocil:actions> |
123634 | ············<ocil:test_action_ref>ocil:ssg- | 123634 | ············<ocil:test_action_ref>ocil:ssg-package_rsh_removed_action:testaction:1</ocil:test_action_ref> |
123635 | ··········</ocil:actions> | 123635 | ··········</ocil:actions> |
123636 | ········</ocil:questionnaire> | 123636 | ········</ocil:questionnaire> |
123637 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_ | 123637 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1"> |
123638 | ··········<ocil:title> | 123638 | ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title> |
123639 | ··········<ocil:actions> | 123639 | ··········<ocil:actions> |
123640 | ············<ocil:test_action_ref>ocil:ssg-sysctl_ | 123640 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref> |
123641 | ··········</ocil:actions> | 123641 | ··········</ocil:actions> |
123642 | ········</ocil:questionnaire> | 123642 | ········</ocil:questionnaire> |
123643 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1"> | ||
123644 | ········ | 123643 | ········<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1"> |
123644 | ··········<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title> | ||
123645 | ··········<ocil:actions> | 123645 | ··········<ocil:actions> |
123646 | ············<ocil:test_action_ref>ocil:ssg- | 123646 | ············<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref> |
123647 | ··········</ocil:actions> | 123647 | ··········</ocil:actions> |
123648 | ········</ocil:questionnaire> | 123648 | ········</ocil:questionnaire> |
123649 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 123649 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_usermod_ocil:questionnaire:1"> |
123650 | ··········<ocil:title> | 123650 | ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·usermod</ocil:title> |
123651 | ··········<ocil:actions> | 123651 | ··········<ocil:actions> |
123652 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_ | 123652 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_usermod_action:testaction:1</ocil:test_action_ref> |
123653 | ··········</ocil:actions> | 123653 | ··········</ocil:actions> |
123654 | ········</ocil:questionnaire> | 123654 | ········</ocil:questionnaire> |
123655 | ········<ocil:questionnaire·id="ocil:ssg-a | 123655 | ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minlen_ocil:questionnaire:1"> |
123656 | ··········<ocil:title> | 123656 | ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Length</ocil:title> |
123657 | ··········<ocil:actions> | 123657 | ··········<ocil:actions> |
123658 | ············<ocil:test_action_ref>ocil:ssg-a | 123658 | ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minlen_action:testaction:1</ocil:test_action_ref> |
123659 | ··········</ocil:actions> | 123659 | ··········</ocil:actions> |
123660 | ········</ocil:questionnaire> | 123660 | ········</ocil:questionnaire> |
123661 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_ocil:questionnaire:1"> | ||
123662 | ········ | 123661 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1"> |
123662 | ··········<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title> | ||
123663 | ··········<ocil:actions> | 123663 | ··········<ocil:actions> |
123664 | ············<ocil:test_action_ref>ocil:ssg- | 123664 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref> |
123665 | ··········</ocil:actions> | 123665 | ··········</ocil:actions> |
123666 | ········</ocil:questionnaire> | 123666 | ········</ocil:questionnaire> |
123667 | ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_banner_enabled_ocil:questionnaire:1"> | ||
123668 | ········ | 123667 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_opasswd_ocil:questionnaire:1"> |
123668 | ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/security/opasswd</ocil:title> | ||
123669 | ··········<ocil:actions> | 123669 | ··········<ocil:actions> |
123670 | ············<ocil:test_action_ref>ocil:ssg-d | 123670 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_opasswd_action:testaction:1</ocil:test_action_ref> |
123671 | ··········</ocil:actions> | 123671 | ··········</ocil:actions> |
123672 | ········</ocil:questionnaire> | 123672 | ········</ocil:questionnaire> |
123673 | ········<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1"> | ||
123674 | ········ | 123673 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chacl_ocil:questionnaire:1"> |
123674 | ··········<ocil:title>Record·Any·Attempts·to·Run·chacl</ocil:title> | ||
123675 | ··········<ocil:actions> | 123675 | ··········<ocil:actions> |
123676 | ············<ocil:test_action_ref>ocil:ssg-a | 123676 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chacl_action:testaction:1</ocil:test_action_ref> |
123677 | ··········</ocil:actions> | 123677 | ··········</ocil:actions> |
123678 | ········</ocil:questionnaire> | 123678 | ········</ocil:questionnaire> |
123679 | ········<ocil:questionnaire·id="ocil:ssg- | 123679 | ········<ocil:questionnaire·id="ocil:ssg-journald_storage_ocil:questionnaire:1"> |
Max diff block lines reached; 936070/948481 bytes (98.69%) of diff not shown. |
Offset 3, 3943 lines modified | Offset 3, 3943 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg- | 10 | ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_info_ocil:questionnaire:1"> |
11 | ······<ocil:title> | 11 | ······<ocil:title>Set·LogLevel·to·INFO</ocil:title> |
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_info_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg- | 16 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_audit_nosuid_ocil:questionnaire:1"> |
17 | ······<ocil:title> | 17 | ······<ocil:title>Add·nosuid·Option·to·/var/log/audit</ocil:title> |
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_nosuid_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1"> |
23 | ······<ocil:title> | 23 | ······<ocil:title>Verify·Owner·on·crontab</ocil:title> |
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg- | 28 | ····<ocil:questionnaire·id="ocil:ssg-package_rsh_removed_ocil:questionnaire:1"> |
29 | ······<ocil:title> | 29 | ······<ocil:title>Uninstall·rsh·Package</ocil:title> |
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-package_rsh_removed_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_ | 34 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1"> |
35 | ······<ocil:title> | 35 | ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title> |
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg-sysctl_ | 37 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1"> | ||
41 | ···· | 40 | ····<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1"> |
41 | ······<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title> | ||
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"> | ||
47 | ···· | 46 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_usermod_ocil:questionnaire:1"> |
47 | ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·usermod</ocil:title> | ||
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_ | 49 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_usermod_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-a | 52 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minlen_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 53 | ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Length</ocil:title> |
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg-a | 55 | ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minlen_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_ocil:questionnaire:1"> | ||
59 | ···· | 58 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1"> |
59 | ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title> | ||
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_banner_enabled_ocil:questionnaire:1"> | ||
65 | ···· | 64 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_opasswd_ocil:questionnaire:1"> |
65 | ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/security/opasswd</ocil:title> | ||
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg-d | 67 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_opasswd_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1"> | ||
71 | ···· | 70 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chacl_ocil:questionnaire:1"> |
71 | ······<ocil:title>Record·Any·Attempts·to·Run·chacl</ocil:title> | ||
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg-a | 73 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chacl_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg- | 76 | ····<ocil:questionnaire·id="ocil:ssg-journald_storage_ocil:questionnaire:1"> |
77 | ······<ocil:title> | 77 | ······<ocil:title>Ensure·journald·is·configured·to·write·log·files·to·persistent·disk</ocil:title> |
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-journald_storage_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg- | 82 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_nodev_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 83 | ······<ocil:title>Add·nodev·Option·to·/var/log</ocil:title> |
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_nodev_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_stig_ocil:questionnaire:1"> | ||
89 | ···· | 88 | ····<ocil:questionnaire·id="ocil:ssg-service_named_disabled_ocil:questionnaire:1"> |
89 | ······<ocil:title>Disable·named·Service</ocil:title> | ||
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-service_named_disabled_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg- | 94 | ····<ocil:questionnaire·id="ocil:ssg-rsyslog_filecreatemode_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 95 | ······<ocil:title>Ensure·rsyslog·Default·File·Permissions·Configured</ocil:title> |
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-rsyslog_filecreatemode_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_rmmod_ocil:questionnaire:1"> | ||
101 | ···· | 100 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nosuid_ocil:questionnaire:1"> |
101 | ······<ocil:title>Add·nosuid·Option·to·/dev/shm</ocil:title> | ||
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nosuid_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg- | 106 | ····<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 107 | ······<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title> |
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1"> | ||
113 | ···· | 112 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_modprobe_ocil:questionnaire:1"> |
113 | ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·modprobe</ocil:title> | ||
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_modprobe_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 118 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_gshadow_ocil:questionnaire:1"> |
119 | ······<ocil:title>Record· | 119 | ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/gshadow</ocil:title> |
120 | ······<ocil:actions> | 120 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_ | 121 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_gshadow_action:testaction:1</ocil:test_action_ref> |
Max diff block lines reached; 891976/904596 bytes (98.60%) of diff not shown. |
Offset 1, 3 lines modified | Offset 1, 3 lines modified | ||
1 | -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary | 1 | -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary |
2 | -rw-r--r--···0········0········0·····19 | 2 | -rw-r--r--···0········0········0·····1980·2025-03-01·08:08:00.000000·control.tar.xz |
3 | -rw-r--r--···0········0········0··1230 | 3 | -rw-r--r--···0········0········0··1230012·2025-03-01·08:08:00.000000·data.tar.xz |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:11"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:11"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·11</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·11</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml">oval:ssg-installed_OS_is_debian11:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml">oval:ssg-installed_OS_is_debian11:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Debian·11.·It·is·a·rendering·of | 40 | configuration·settings·for·Debian·11.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 76227, 15 lines modified | Offset 76227, 15 lines modified | ||
76227 | ··············<xccdf-1.2:check-content-ref·href="ssg-debian11-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> | 76227 | ··············<xccdf-1.2:check-content-ref·href="ssg-debian11-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> |
76228 | ············</xccdf-1.2:check> | 76228 | ············</xccdf-1.2:check> |
76229 | ··········</xccdf-1.2:Rule> | 76229 | ··········</xccdf-1.2:Rule> |
76230 | ········</xccdf-1.2:Group> | 76230 | ········</xccdf-1.2:Group> |
76231 | ······</xccdf-1.2:Group> | 76231 | ······</xccdf-1.2:Group> |
76232 | ····</xccdf-1.2:Benchmark> | 76232 | ····</xccdf-1.2:Benchmark> |
76233 | ··</ds:component> | 76233 | ··</ds:component> |
76234 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-oval.xml"·timestamp="2025-0 | 76234 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-oval.xml"·timestamp="2025-03-01T22:08:00"> |
76235 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 76235 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
76236 | ······<oval-def:generator> | 76236 | ······<oval-def:generator> |
76237 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 76237 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
76238 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 76238 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
76239 | ········<oval:schema_version>5.11</oval:schema_version> | 76239 | ········<oval:schema_version>5.11</oval:schema_version> |
76240 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 76240 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
76241 | ······</oval-def:generator> | 76241 | ······</oval-def:generator> |
Offset 93180, 2500 lines modified | Offset 93180, 2500 lines modified | ||
93180 | ············</oval-def:arithmetic> | 93180 | ············</oval-def:arithmetic> |
93181 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 93181 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
93182 | ··········</oval-def:arithmetic> | 93182 | ··········</oval-def:arithmetic> |
93183 | ········</oval-def:local_variable> | 93183 | ········</oval-def:local_variable> |
93184 | ······</oval-def:variables> | 93184 | ······</oval-def:variables> |
93185 | ····</oval-def:oval_definitions> | 93185 | ····</oval-def:oval_definitions> |
93186 | ··</ds:component> | 93186 | ··</ds:component> |
93187 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-ocil.xml"·timestamp="2025-0 | 93187 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
93188 | ····<ocil:ocil> | 93188 | ····<ocil:ocil> |
93189 | ······<ocil:generator> | 93189 | ······<ocil:generator> |
93190 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 93190 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
93191 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 93191 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
93192 | ········<ocil:schema_version>2.0</ocil:schema_version> | 93192 | ········<ocil:schema_version>2.0</ocil:schema_version> |
93193 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 93193 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
93194 | ······</ocil:generator> | 93194 | ······</ocil:generator> |
93195 | ······<ocil:questionnaires> | 93195 | ······<ocil:questionnaires> |
93196 | ········<ocil:questionnaire·id="ocil:ssg- | 93196 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1"> |
93197 | ··········<ocil:title> | 93197 | ··········<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title> |
93198 | ··········<ocil:actions> | 93198 | ··········<ocil:actions> |
93199 | ············<ocil:test_action_ref>ocil:ssg- | 93199 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref> |
93200 | ··········</ocil:actions> | 93200 | ··········</ocil:actions> |
93201 | ········</ocil:questionnaire> | 93201 | ········</ocil:questionnaire> |
93202 | ········<ocil:questionnaire·id="ocil:ssg- | 93202 | ········<ocil:questionnaire·id="ocil:ssg-snmpd_not_default_password_ocil:questionnaire:1"> |
93203 | ··········<ocil:title>Ensure· | 93203 | ··········<ocil:title>Ensure·Default·SNMP·Password·Is·Not·Used</ocil:title> |
93204 | ··········<ocil:actions> | 93204 | ··········<ocil:actions> |
93205 | ············<ocil:test_action_ref>ocil:ssg- | 93205 | ············<ocil:test_action_ref>ocil:ssg-snmpd_not_default_password_action:testaction:1</ocil:test_action_ref> |
93206 | ··········</ocil:actions> | 93206 | ··········</ocil:actions> |
93207 | ········</ocil:questionnaire> | 93207 | ········</ocil:questionnaire> |
93208 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> | ||
93209 | ········ | 93208 | ········<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1"> |
93209 | ··········<ocil:title>Disable·Host-Based·Authentication</ocil:title> | ||
93210 | ··········<ocil:actions> | 93210 | ··········<ocil:actions> |
93211 | ············<ocil:test_action_ref>ocil:ssg- | 93211 | ············<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref> |
93212 | ··········</ocil:actions> | 93212 | ··········</ocil:actions> |
93213 | ········</ocil:questionnaire> | 93213 | ········</ocil:questionnaire> |
93214 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_x86_vsyscall_emulation_ocil:questionnaire:1"> | ||
93215 | ········ | 93214 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1"> |
93215 | ··········<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rename</ocil:title> | ||
93216 | ··········<ocil:actions> | 93216 | ··········<ocil:actions> |
93217 | ············<ocil:test_action_ref>ocil:ssg- | 93217 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1</ocil:test_action_ref> |
93218 | ··········</ocil:actions> | 93218 | ··········</ocil:actions> |
93219 | ········</ocil:questionnaire> | 93219 | ········</ocil:questionnaire> |
93220 | ········<ocil:questionnaire·id="ocil:ssg-s | 93220 | ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1"> |
93221 | ··········<ocil:title>D | 93221 | ··········<ocil:title>Disable·Kerberos·Authentication</ocil:title> |
93222 | ··········<ocil:actions> | 93222 | ··········<ocil:actions> |
93223 | ············<ocil:test_action_ref>ocil:ssg-s | 93223 | ············<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref> |
93224 | ··········</ocil:actions> | 93224 | ··········</ocil:actions> |
93225 | ········</ocil:questionnaire> | 93225 | ········</ocil:questionnaire> |
93226 | ········<ocil:questionnaire·id="ocil:ssg- | 93226 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_filter_ocil:questionnaire:1"> |
93227 | ··········<ocil:title> | 93227 | ··········<ocil:title>Enable·use·of·Berkeley·Packet·Filter·with·seccomp</ocil:title> |
93228 | ··········<ocil:actions> | 93228 | ··········<ocil:actions> |
93229 | ············<ocil:test_action_ref>ocil:ssg- | 93229 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_filter_action:testaction:1</ocil:test_action_ref> |
93230 | ··········</ocil:actions> | 93230 | ··········</ocil:actions> |
93231 | ········</ocil:questionnaire> | 93231 | ········</ocil:questionnaire> |
93232 | ········<ocil:questionnaire·id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1"> | ||
93233 | ········ | 93232 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1"> |
93233 | ··········<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title> | ||
93234 | ··········<ocil:actions> | 93234 | ··········<ocil:actions> |
93235 | ············<ocil:test_action_ref>ocil:ssg- | 93235 | ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref> |
93236 | ··········</ocil:actions> | 93236 | ··········</ocil:actions> |
93237 | ········</ocil:questionnaire> | 93237 | ········</ocil:questionnaire> |
93238 | ········<ocil:questionnaire·id="ocil:ssg- | 93238 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1"> |
93239 | ··········<ocil:title> | 93239 | ··········<ocil:title>Enable·support·for·BUG()</ocil:title> |
93240 | ··········<ocil:actions> | 93240 | ··········<ocil:actions> |
93241 | ············<ocil:test_action_ref>ocil:ssg- | 93241 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref> |
93242 | ··········</ocil:actions> | 93242 | ··········</ocil:actions> |
93243 | ········</ocil:questionnaire> | 93243 | ········</ocil:questionnaire> |
93244 | ········<ocil:questionnaire·id="ocil:ssg- | 93244 | ········<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1"> |
93245 | ··········<ocil:title> | 93245 | ··········<ocil:title>Disable·XDMCP·in·GDM</ocil:title> |
93246 | ··········<ocil:actions> | 93246 | ··········<ocil:actions> |
93247 | ············<ocil:test_action_ref>ocil:ssg- | 93247 | ············<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref> |
93248 | ··········</ocil:actions> | 93248 | ··········</ocil:actions> |
93249 | ········</ocil:questionnaire> | 93249 | ········</ocil:questionnaire> |
93250 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_passwd_ocil:questionnaire:1"> | ||
93251 | ········ | 93250 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1"> |
93251 | ··········<ocil:title>Configure·ARP·filtering·for·All·IPv4·Interfaces</ocil:title> | ||
93252 | ··········<ocil:actions> | 93252 | ··········<ocil:actions> |
93253 | ············<ocil:test_action_ref>ocil:ssg- | 93253 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1</ocil:test_action_ref> |
93254 | ··········</ocil:actions> | 93254 | ··········</ocil:actions> |
93255 | ········</ocil:questionnaire> | 93255 | ········</ocil:questionnaire> |
93256 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_ | 93256 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1"> |
93257 | ··········<ocil:title>Verify·Permissions·on·Backup· | 93257 | ··········<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title> |
93258 | ··········<ocil:actions> | 93258 | ··········<ocil:actions> |
93259 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_ | 93259 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref> |
93260 | ··········</ocil:actions> | 93260 | ··········</ocil:actions> |
93261 | ········</ocil:questionnaire> | 93261 | ········</ocil:questionnaire> |
93262 | ········<ocil:questionnaire·id="ocil:ssg- | 93262 | ········<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1"> |
Max diff block lines reached; 739712/751665 bytes (98.41%) of diff not shown. |
Offset 3, 2491 lines modified | Offset 3, 2491 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg- | 10 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1"> |
11 | ······<ocil:title> | 11 | ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title> |
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg- | 16 | ····<ocil:questionnaire·id="ocil:ssg-snmpd_not_default_password_ocil:questionnaire:1"> |
17 | ······<ocil:title>Ensure· | 17 | ······<ocil:title>Ensure·Default·SNMP·Password·Is·Not·Used</ocil:title> |
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-snmpd_not_default_password_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> | ||
23 | ···· | 22 | ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1"> |
23 | ······<ocil:title>Disable·Host-Based·Authentication</ocil:title> | ||
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_x86_vsyscall_emulation_ocil:questionnaire:1"> | ||
29 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1"> |
29 | ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rename</ocil:title> | ||
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-s | 34 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1"> |
35 | ······<ocil:title>D | 35 | ······<ocil:title>Disable·Kerberos·Authentication</ocil:title> |
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg-s | 37 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 40 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_filter_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 41 | ······<ocil:title>Enable·use·of·Berkeley·Packet·Filter·with·seccomp</ocil:title> |
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_filter_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1"> | ||
47 | ···· | 46 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1"> |
47 | ······<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title> | ||
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 52 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 53 | ······<ocil:title>Enable·support·for·BUG()</ocil:title> |
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 59 | ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title> |
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_passwd_ocil:questionnaire:1"> | ||
65 | ···· | 64 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1"> |
65 | ······<ocil:title>Configure·ARP·filtering·for·All·IPv4·Interfaces</ocil:title> | ||
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_ | 70 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1"> |
71 | ······<ocil:title>Verify·Permissions·on·Backup· | 71 | ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title> |
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_ | 73 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg- | 76 | ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1"> |
77 | ······<ocil:title> | 77 | ······<ocil:title>IOMMU·configuration·directive</ocil:title> |
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-grub2_enable_iommu_force_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ocil:questionnaire:1"> | ||
83 | ···· | 82 | ····<ocil:questionnaire·id="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1"> |
83 | ······<ocil:title>Ensure·SELinux·is·Not·Disabled</ocil:title> | ||
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-selinux_not_disabled_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1"> | ||
89 | ···· | 88 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_gshadow_ocil:questionnaire:1"> |
89 | ······<ocil:title>Verify·Group·Who·Owns·Backup·gshadow·File</ocil:title> | ||
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg-gru | 91 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-package_ | 94 | ····<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 95 | ······<ocil:title>Ensure·logrotate·is·Installed</ocil:title> |
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg-package_ | 97 | ········<ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1"> |
101 | ······<ocil:title>Ensure· | 101 | ······<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title> |
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_library_dirs_ocil:questionnaire:1"> | ||
107 | ···· | 106 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1"> |
107 | ······<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title> | ||
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1"> | ||
113 | ···· | 112 | ····<ocil:questionnaire·id="ocil:ssg-set_ip6tables_default_rule_ocil:questionnaire:1"> |
113 | ······<ocil:title>Set·Default·ip6tables·Policy·for·Incoming·Packets</ocil:title> | ||
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-set_ip6tables_default_rule_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg- | 118 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1"> |
119 | ······<ocil:title> | 119 | ······<ocil:title>Verify·Permissions·on·group·File</ocil:title> |
120 | ······<ocil:actions> | 120 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg- | 121 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_group_action:testaction:1</ocil:test_action_ref> |
Max diff block lines reached; 703452/715679 bytes (98.29%) of diff not shown. |
Offset 21, 23 lines modified | Offset 21, 23 lines modified | ||
21 | ····<ds:checks> | 21 | ····<ds:checks> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-oval.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-oval.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-ocil.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-ocil.xml"/> |
24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-cpe-oval.xml"/> | 24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-cpe-oval.xml"/> |
25 | ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-oval-definitions-bookworm.xml.bz2"·xlink:href="https://www.debian.org/security/oval/oval-definitions-bookworm.xml.bz2"/> | 25 | ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-oval-definitions-bookworm.xml.bz2"·xlink:href="https://www.debian.org/security/oval/oval-definitions-bookworm.xml.bz2"/> |
26 | ····</ds:checks> | 26 | ····</ds:checks> |
27 | ··</ds:data-stream> | 27 | ··</ds:data-stream> |
28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-cpe-dictionary.xml"·timestamp="2025-0 | 28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
30 | ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:12"> | 30 | ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:12"> |
31 | ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·12</cpe-dict:title> | 31 | ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·12</cpe-dict:title> |
32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml">oval:ssg-installed_OS_is_debian12:def:1</cpe-dict:check> | 32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml">oval:ssg-installed_OS_is_debian12:def:1</cpe-dict:check> |
33 | ······</cpe-dict:cpe-item> | 33 | ······</cpe-dict:cpe-item> |
34 | ····</cpe-dict:cpe-list> | 34 | ····</cpe-dict:cpe-list> |
35 | ··</ds:component> | 35 | ··</ds:component> |
36 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-xccdf.xml"·timestamp="2025-0 | 36 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
37 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 37 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
38 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 38 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
39 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·12</xccdf-1.2:title> | 39 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·12</xccdf-1.2:title> |
40 | ······<xccdf-1.2:description> | 40 | ······<xccdf-1.2:description> |
41 | ········This·guide·presents·a·catalog·of·security-relevant | 41 | ········This·guide·presents·a·catalog·of·security-relevant |
42 | configuration·settings·for·Debian·12.·It·is·a·rendering·of | 42 | configuration·settings·for·Debian·12.·It·is·a·rendering·of |
43 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 43 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 110245, 15 lines modified | Offset 110245, 15 lines modified | ||
110245 | ··············<xccdf-1.2:check-content-ref·href="ssg-debian12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> | 110245 | ··············<xccdf-1.2:check-content-ref·href="ssg-debian12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> |
110246 | ············</xccdf-1.2:check> | 110246 | ············</xccdf-1.2:check> |
110247 | ··········</xccdf-1.2:Rule> | 110247 | ··········</xccdf-1.2:Rule> |
110248 | ········</xccdf-1.2:Group> | 110248 | ········</xccdf-1.2:Group> |
110249 | ······</xccdf-1.2:Group> | 110249 | ······</xccdf-1.2:Group> |
110250 | ····</xccdf-1.2:Benchmark> | 110250 | ····</xccdf-1.2:Benchmark> |
110251 | ··</ds:component> | 110251 | ··</ds:component> |
110252 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-oval.xml"·timestamp="2025-0 | 110252 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-oval.xml"·timestamp="2025-03-01T22:08:00"> |
110253 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 110253 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
110254 | ······<oval-def:generator> | 110254 | ······<oval-def:generator> |
110255 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 110255 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
110256 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 110256 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
110257 | ········<oval:schema_version>5.11</oval:schema_version> | 110257 | ········<oval:schema_version>5.11</oval:schema_version> |
110258 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 110258 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
110259 | ······</oval-def:generator> | 110259 | ······</oval-def:generator> |
Offset 140530, 7923 lines modified | Offset 140530, 7930 lines modified | ||
140530 | ············</oval-def:arithmetic> | 140530 | ············</oval-def:arithmetic> |
140531 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 140531 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
140532 | ··········</oval-def:arithmetic> | 140532 | ··········</oval-def:arithmetic> |
140533 | ········</oval-def:local_variable> | 140533 | ········</oval-def:local_variable> |
140534 | ······</oval-def:variables> | 140534 | ······</oval-def:variables> |
140535 | ····</oval-def:oval_definitions> | 140535 | ····</oval-def:oval_definitions> |
140536 | ··</ds:component> | 140536 | ··</ds:component> |
140537 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-ocil.xml"·timestamp="2025-0 | 140537 | ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
140538 | ····<ocil:ocil> | 140538 | ····<ocil:ocil> |
140539 | ······<ocil:generator> | 140539 | ······<ocil:generator> |
140540 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 140540 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
140541 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 140541 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
140542 | ········<ocil:schema_version>2.0</ocil:schema_version> | 140542 | ········<ocil:schema_version>2.0</ocil:schema_version> |
140543 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 140543 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
140544 | ······</ocil:generator> | 140544 | ······</ocil:generator> |
140545 | ······<ocil:questionnaires> | 140545 | ······<ocil:questionnaires> |
140546 | ········<ocil:questionnaire·id="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1"> | ||
140547 | ··········<ocil:title>Ensure·SMAP·is·not·disabled·during·boot</ocil:title> | ||
140548 | ··········<ocil:actions> | ||
140549 | ············<ocil:test_action_ref>ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1</ocil:test_action_ref> | ||
140550 | ··········</ocil:actions> | ||
140551 | ········</ocil:questionnaire> | ||
140546 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"> | 140552 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"> |
140547 | ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title> | 140553 | ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title> |
140548 | ··········<ocil:actions> | 140554 | ··········<ocil:actions> |
140549 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref> | 140555 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref> |
140550 | ··········</ocil:actions> | 140556 | ··········</ocil:actions> |
140551 | ········</ocil:questionnaire> | 140557 | ········</ocil:questionnaire> |
140552 | ········<ocil:questionnaire·id="ocil:ssg- | 140558 | ········<ocil:questionnaire·id="ocil:ssg-dir_system_commands_root_owned_ocil:questionnaire:1"> |
140553 | ··········<ocil:title> | 140559 | ··········<ocil:title>Verify·that·system·commands·directories·have·root·ownership</ocil:title> |
140554 | ··········<ocil:actions> | 140560 | ··········<ocil:actions> |
140555 | ············<ocil:test_action_ref>ocil:ssg- | 140561 | ············<ocil:test_action_ref>ocil:ssg-dir_system_commands_root_owned_action:testaction:1</ocil:test_action_ref> |
140556 | ··········</ocil:actions> | 140562 | ··········</ocil:actions> |
140557 | ········</ocil:questionnaire> | 140563 | ········</ocil:questionnaire> |
140558 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_ocil:questionnaire:1"> | ||
140559 | ········ | 140564 | ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1"> |
140565 | ··········<ocil:title>Disable·SSH·root·Login·with·a·Password·(Insecure)</ocil:title> | ||
140560 | ··········<ocil:actions> | 140566 | ··········<ocil:actions> |
140561 | ············<ocil:test_action_ref>ocil:ssg-s | 140567 | ············<ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref> |
140562 | ··········</ocil:actions> | 140568 | ··········</ocil:actions> |
140563 | ········</ocil:questionnaire> | 140569 | ········</ocil:questionnaire> |
140564 | ········<ocil:questionnaire·id="ocil:ssg- | 140570 | ········<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1"> |
140565 | ··········<ocil:title>Disable· | 140571 | ··········<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title> |
140566 | ··········<ocil:actions> | 140572 | ··········<ocil:actions> |
140567 | ············<ocil:test_action_ref>ocil:ssg- | 140573 | ············<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref> |
140568 | ··········</ocil:actions> | 140574 | ··········</ocil:actions> |
140569 | ········</ocil:questionnaire> | 140575 | ········</ocil:questionnaire> |
140570 | ········<ocil:questionnaire·id="ocil:ssg-audit | 140576 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1"> |
140571 | ··········<ocil:title> | 140577 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title> |
140572 | ··········<ocil:actions> | 140578 | ··········<ocil:actions> |
140573 | ············<ocil:test_action_ref>ocil:ssg-audit | 140579 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref> |
140574 | ··········</ocil:actions> | 140580 | ··········</ocil:actions> |
140575 | ········</ocil:questionnaire> | 140581 | ········</ocil:questionnaire> |
140576 | ········<ocil:questionnaire·id="ocil:ssg-a | 140582 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1"> |
140577 | ··········<ocil:title> | 140583 | ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title> |
140578 | ··········<ocil:actions> | 140584 | ··········<ocil:actions> |
140579 | ············<ocil:test_action_ref>ocil:ssg-a | 140585 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref> |
140580 | ··········</ocil:actions> | 140586 | ··········</ocil:actions> |
140581 | ········</ocil:questionnaire> | 140587 | ········</ocil:questionnaire> |
140582 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_efi_user_cfg_ocil:questionnaire:1"> | ||
140583 | ········ | 140588 | ········<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1"> |
140589 | ··········<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title> | ||
140584 | ··········<ocil:actions> | 140590 | ··········<ocil:actions> |
140585 | ············<ocil:test_action_ref>ocil:ssg- | 140591 | ············<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref> |
140586 | ··········</ocil:actions> | 140592 | ··········</ocil:actions> |
140587 | ········</ocil:questionnaire> | 140593 | ········</ocil:questionnaire> |
140588 | ········<ocil:questionnaire·id="ocil:ssg- | 140594 | ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1"> |
140589 | ··········<ocil:title> | 140595 | ··········<ocil:title>Disable·SSH·Root·Login</ocil:title> |
140590 | ··········<ocil:actions> | 140596 | ··········<ocil:actions> |
140591 | ············<ocil:test_action_ref>ocil:ssg- | 140597 | ············<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref> |
140592 | ··········</ocil:actions> | 140598 | ··········</ocil:actions> |
140593 | ········</ocil:questionnaire> | 140599 | ········</ocil:questionnaire> |
140594 | ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_ | 140600 | ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1"> |
140595 | ··········<ocil:title>Disable· | 140601 | ··········<ocil:title>Disable·X11·Forwarding</ocil:title> |
140596 | ··········<ocil:actions> | 140602 | ··········<ocil:actions> |
140597 | ············<ocil:test_action_ref>ocil:ssg-sshd_disable_ | 140603 | ············<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref> |
140598 | ··········</ocil:actions> | 140604 | ··········</ocil:actions> |
140599 | ········</ocil:questionnaire> | 140605 | ········</ocil:questionnaire> |
140600 | ········<ocil:questionnaire·id="ocil:ssg- | 140606 | ········<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1"> |
140601 | ··········<ocil:title> | 140607 | ··········<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title> |
140602 | ··········<ocil:actions> | 140608 | ··········<ocil:actions> |
140603 | ············<ocil:test_action_ref>ocil:ssg- | 140609 | ············<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref> |
140604 | ··········</ocil:actions> | 140610 | ··········</ocil:actions> |
140605 | ········</ocil:questionnaire> | 140611 | ········</ocil:questionnaire> |
140606 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_shadow_ocil:questionnaire:1"> | ||
140607 | ········ | 140612 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1"> |
140613 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmod</ocil:title> | ||
Max diff block lines reached; 1232090/1243917 bytes (99.05%) of diff not shown. |
Offset 3, 7914 lines modified | Offset 3, 7921 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1"> | ||
11 | ······<ocil:title>Ensure·SMAP·is·not·disabled·during·boot</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
10 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"> | 16 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"> |
11 | ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title> | 17 | ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title> |
12 | ······<ocil:actions> | 18 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref> | 19 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 20 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-dir_system_commands_root_owned_ocil:questionnaire:1"> |
17 | ······<ocil:title> | 23 | ······<ocil:title>Verify·that·system·commands·directories·have·root·ownership</ocil:title> |
18 | ······<ocil:actions> | 24 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-dir_system_commands_root_owned_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 26 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_ocil:questionnaire:1"> | ||
23 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1"> |
29 | ······<ocil:title>Disable·SSH·root·Login·with·a·Password·(Insecure)</ocil:title> | ||
24 | ······<ocil:actions> | 30 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg-s | 31 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 32 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1"> |
29 | ······<ocil:title>Disable· | 35 | ······<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title> |
30 | ······<ocil:actions> | 36 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 38 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1"> | ||
35 | ···· | 40 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1"> |
41 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title> | ||
36 | ······<ocil:actions> | 42 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg-audit | 43 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 44 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-a | 46 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 47 | ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title> |
42 | ······<ocil:actions> | 48 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg-a | 49 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 50 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_efi_user_cfg_ocil:questionnaire:1"> | ||
47 | ···· | 52 | ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1"> |
53 | ······<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title> | ||
48 | ······<ocil:actions> | 54 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 56 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 59 | ······<ocil:title>Disable·SSH·Root·Login</ocil:title> |
54 | ······<ocil:actions> | 60 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 62 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_ | 64 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1"> |
59 | ······<ocil:title>Disable· | 65 | ······<ocil:title>Disable·X11·Forwarding</ocil:title> |
60 | ······<ocil:actions> | 66 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_ | 67 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 68 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1"> |
65 | ······<ocil:title> | 71 | ······<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title> |
66 | ······<ocil:actions> | 72 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 74 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_shadow_ocil:questionnaire:1"> | ||
71 | ···· | 76 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1"> |
77 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmod</ocil:title> | ||
72 | ······<ocil:actions> | 78 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmod_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 80 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1"> | ||
77 | ···· | 82 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_syslog_ocil:questionnaire:1"> |
83 | ······<ocil:title>Verify·Permissions·on·/var/log/syslog·File</ocil:title> | ||
78 | ······<ocil:actions> | 84 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_syslog_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 86 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg- | 88 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1"> |
83 | ······<ocil:title>En | 89 | ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title> |
84 | ······<ocil:actions> | 90 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 92 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_ocil:questionnaire:1"> | ||
89 | ···· | 94 | ····<ocil:questionnaire·id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1"> |
95 | ······<ocil:title>Ensure·gnutls-utils·is·installed</ocil:title> | ||
90 | ······<ocil:actions> | 96 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 98 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 101 | ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title> |
96 | ······<ocil:actions> | 102 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 104 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-audit_ | 106 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_tallylog_ocil:questionnaire:1"> |
101 | ······<ocil:title> | 107 | ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·tallylog</ocil:title> |
102 | ······<ocil:actions> | 108 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg-audit_ | 109 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_tallylog_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 110 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg- | 112 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 113 | ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Different·Categories</ocil:title> |
108 | ······<ocil:actions> | 114 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minclass_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 116 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg- | 118 | ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 119 | ······<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title> |
114 | ······<ocil:actions> | 120 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 121 | ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 122 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 123 | ····</ocil:questionnaire> |
Max diff block lines reached; 1174183/1186571 bytes (98.96%) of diff not shown. |
Offset 1, 3 lines modified | Offset 1, 3 lines modified | ||
1 | -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary | 1 | -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary |
2 | -rw-r--r--···0········0········0····18 | 2 | -rw-r--r--···0········0········0····18204·2025-03-01·08:08:00.000000·control.tar.xz |
3 | -rw-r--r--···0········0········0·37082 | 3 | -rw-r--r--···0········0········0·37082148·2025-03-01·08:08:00.000000·data.tar.xz |
Offset 8560, 18 lines modified | Offset 8560, 18 lines modified | ||
000216f0:·6b0a·616e·6420·7573·6520·7468·6520·696e··k.and·use·the·in | 000216f0:·6b0a·616e·6420·7573·6520·7468·6520·696e··k.and·use·the·in | ||
00021700:·666f·726d·6174·696f·6e20·746f·2070·6f74··formation·to·pot | 00021700:·666f·726d·6174·696f·6e20·746f·2070·6f74··formation·to·pot | ||
00021710:·656e·7469·616c·6c79·2063·6f6d·7072·6f6d··entially·comprom | 00021710:·656e·7469·616c·6c79·2063·6f6d·7072·6f6d··entially·comprom | ||
00021720:·6973·6520·7468·6520·696e·7465·6772·6974··ise·the·integrit | 00021720:·6973·6520·7468·6520·696e·7465·6772·6974··ise·the·integrit | ||
00021730:·7920·6f66·2074·6865·2073·7973·7465·6d20··y·of·the·system· | 00021730:·7920·6f66·2074·6865·2073·7973·7465·6d20··y·of·the·system· | ||
00021740:·616e·640a·6e65·7477·6f72·6b28·7329·2e0a··and.network(s).. | 00021740:·616e·640a·6e65·7477·6f72·6b28·7329·2e0a··and.network(s).. | ||
00021750:·2020·3c2f·7464·3e0a·2020·3c74·643e·7661····</td>.··<td>va | 00021750:·2020·3c2f·7464·3e0a·2020·3c74·643e·7661····</td>.··<td>va | ||
00021760:·725f·736e·6d70·645f·72 | 00021760:·725f·736e·6d70·645f·726f·5f73·7472·696e··r_snmpd_ro_strin | ||
00021770:·673d·6368·616e·6765·6d65·72 | 00021770:·673d·6368·616e·6765·6d65·726f·3c62·722f··g=changemero<br/ | ||
00021780:·3e76·6172·5f73·6e6d·7064·5f72· | 00021780:·3e76·6172·5f73·6e6d·7064·5f72·775f·7374··>var_snmpd_rw_st | ||
00021790:·7269·6e67·3d63·6861·6e67·656d·6572· | 00021790:·7269·6e67·3d63·6861·6e67·656d·6572·773c··ring=changemerw< | ||
000217a0:·2f74·643e·0a3c·2f74·723e·0a3c·7472·3e0a··/td>.</tr>.<tr>. | 000217a0:·2f74·643e·0a3c·2f74·723e·0a3c·7472·3e0a··/td>.</tr>.<tr>. | ||
000217b0:·2020·3c74·643e·5343·2d35·3c2f·7464·3e0a····<td>SC-5</td>. | 000217b0:·2020·3c74·643e·5343·2d35·3c2f·7464·3e0a····<td>SC-5</td>. | ||
000217c0:·2020·3c74·643e·4e2f·413c·2f74·643e·0a20····<td>N/A</td>.· | 000217c0:·2020·3c74·643e·4e2f·413c·2f74·643e·0a20····<td>N/A</td>.· | ||
000217d0:·203c·7464·3e43·6f6e·6669·6775·7265·204b···<td>Configure·K | 000217d0:·203c·7464·3e43·6f6e·6669·6775·7265·204b···<td>Configure·K | ||
000217e0:·6572·6e65·6c20·746f·2052·6174·6520·4c69··ernel·to·Rate·Li | 000217e0:·6572·6e65·6c20·746f·2052·6174·6520·4c69··ernel·to·Rate·Li | ||
000217f0:·6d69·7420·5365·6e64·696e·6720·6f66·2044··mit·Sending·of·D | 000217f0:·6d69·7420·5365·6e64·696e·6720·6f66·2044··mit·Sending·of·D | ||
00021800:·7570·6c69·6361·7465·2054·4350·2041·636b··uplicate·TCP·Ack | 00021800:·7570·6c69·6361·7465·2054·4350·2041·636b··uplicate·TCP·Ack |
Offset 2919, 16 lines modified | Offset 2919, 16 lines modified | ||
2919 | ··············································································network·management | 2919 | ··············································································network·management |
2920 | ··············································································protocol·(SNMP) | 2920 | ··············································································protocol·(SNMP) |
2921 | ··············································································community·strings | 2921 | ··············································································community·strings |
2922 | ··············································································must·be·changed·to | 2922 | ··············································································must·be·changed·to |
2923 | ··································Edit·/etc/snmp/snmpd.conf,·remove·or·change·maintain·security. | 2923 | ··································Edit·/etc/snmp/snmpd.conf,·remove·or·change·maintain·security. |
2924 | ··································the·default·community·strings·of·public·and·If·the·service·is | 2924 | ··································the·default·community·strings·of·public·and·If·the·service·is |
2925 | ··································private.·This·profile·configures·new·read-··running·with·the | 2925 | ··································private.·This·profile·configures·new·read-··running·with·the |
2926 | ········N/·Ensure·Default·SNMP····only·community·string·to·changemero·and·····default·············var_snmpd_r | 2926 | ········N/·Ensure·Default·SNMP····only·community·string·to·changemero·and·····default·············var_snmpd_ro_string=changemero |
2927 | IA-5(e)·A··Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·····var_snmpd_r | 2927 | IA-5(e)·A··Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·····var_snmpd_rw_string=changemerw |
2928 | ··································Once·the·default·community·strings·have·····then·anyone·can | 2928 | ··································Once·the·default·community·strings·have·····then·anyone·can |
2929 | ··································been·changed,·restart·the·SNMP·service:·····gather·data·about | 2929 | ··································been·changed,·restart·the·SNMP·service:·····gather·data·about |
2930 | ··································$·sudo·systemctl·restart·snmpd··············the·system·and·the | 2930 | ··································$·sudo·systemctl·restart·snmpd··············the·system·and·the |
2931 | ··············································································network·and·use·the | 2931 | ··············································································network·and·use·the |
2932 | ··············································································information·to | 2932 | ··············································································information·to |
2933 | ··············································································potentially | 2933 | ··············································································potentially |
2934 | ··············································································compromise·the | 2934 | ··············································································compromise·the |
Offset 4070, 15 lines modified | Offset 4070, 15 lines modified | ||
4070 | <tt>RekeyLimit</tt>. | 4070 | <tt>RekeyLimit</tt>. |
4071 | ··</td> | 4071 | ··</td> |
4072 | ··<td·xml:lang="en-US"> | 4072 | ··<td·xml:lang="en-US"> |
4073 | By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling | 4073 | By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling |
4074 | time-based·limit,·effects·of·potential·attacks·against | 4074 | time-based·limit,·effects·of·potential·attacks·against |
4075 | encryption·keys·are·limited. | 4075 | encryption·keys·are·limited. |
4076 | ··</td> | 4076 | ··</td> |
4077 | ··<td>var_ssh_client_rekey_limit_ | 4077 | ··<td>var_ssh_client_rekey_limit_size=1G<br/>var_ssh_client_rekey_limit_time=1hour</td> |
4078 | </tr> | 4078 | </tr> |
4079 | <tr> | 4079 | <tr> |
4080 | ··<td></td> | 4080 | ··<td></td> |
4081 | ··<td>N/A</td> | 4081 | ··<td>N/A</td> |
4082 | ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td> | 4082 | ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td> |
4083 | ··<td·xml:lang="en-US"> | 4083 | ··<td·xml:lang="en-US"> |
4084 | To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure | 4084 | To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure |
Offset 4133, 15 lines modified | Offset 4133, 15 lines modified | ||
4133 | <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre> | 4133 | <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre> |
4134 | ··</td> | 4134 | ··</td> |
4135 | ··<td·xml:lang="en-US"> | 4135 | ··<td·xml:lang="en-US"> |
4136 | By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling | 4136 | By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling |
4137 | time-based·limit,·effects·of·potential·attacks·against | 4137 | time-based·limit,·effects·of·potential·attacks·against |
4138 | encryption·keys·are·limited. | 4138 | encryption·keys·are·limited. |
4139 | ··</td> | 4139 | ··</td> |
4140 | ··<td>var_rekey_limit_ | 4140 | ··<td>var_rekey_limit_size=1G<br/>var_rekey_limit_time=1hour</td> |
4141 | </tr> | 4141 | </tr> |
4142 | <tr> | 4142 | <tr> |
4143 | ··<td></td> | 4143 | ··<td></td> |
4144 | ··<td>N/A</td> | 4144 | ··<td>N/A</td> |
4145 | ··<td>SSH·server·uses·strong·entropy·to·seed</td> | 4145 | ··<td>SSH·server·uses·strong·entropy·to·seed</td> |
4146 | ··<td·xml:lang="en-US"> | 4146 | ··<td·xml:lang="en-US"> |
4147 | To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file. | 4147 | To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file. |
Offset 3341, 16 lines modified | Offset 3341, 16 lines modified | ||
3341 | ··················································································································options,·which·can | 3341 | ··················································································································options,·which·can |
3342 | ··················································································································help·protect | 3342 | ··················································································································help·protect |
3343 | ··················································································································programs·which·use | 3343 | ··················································································································programs·which·use |
3344 | ··················································································································it. | 3344 | ··················································································································it. |
3345 | ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the | 3345 | ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the |
3346 | ·························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the | 3346 | ·························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the |
3347 | ········Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and | 3347 | ········Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and |
3348 | ·····N/·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_ | 3348 | ·····N/·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_size=1G |
3349 | ·····A··renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_ | 3349 | ·····A··renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_time=1hour |
3350 | ········for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks | 3350 | ········for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks |
3351 | ·························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption | 3351 | ·························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption |
3352 | ·························containing·definition·of·RekeyLimit.·····················································keys·are·limited. | 3352 | ·························containing·definition·of·RekeyLimit.·····················································keys·are·limited. |
3353 | ··················································································································Some·SSH | 3353 | ··················································································································Some·SSH |
3354 | ··················································································································implementations·use | 3354 | ··················································································································implementations·use |
3355 | ··················································································································the·openssl·library | 3355 | ··················································································································the·openssl·library |
3356 | ··················································································································for·entropy,·which | 3356 | ··················································································································for·entropy,·which |
Offset 3401, 16 lines modified | Offset 3401, 16 lines modified | ||
3401 | ··················································································································generator·used·by | 3401 | ··················································································································generator·used·by |
3402 | ··················································································································SSH·would·be·known | 3402 | ··················································································································SSH·would·be·known |
3403 | ··················································································································to·potential | 3403 | ··················································································································to·potential |
3404 | ··················································································································attackers. | 3404 | ··················································································································attackers. |
3405 | ··················································································································By·decreasing·the | 3405 | ··················································································································By·decreasing·the |
3406 | ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the | 3406 | ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the |
3407 | ········Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and | 3407 | ········Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and |
3408 | ·····N/·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_ | 3408 | ·····N/·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_size=1G |
3409 | ·····A··renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_ | 3409 | ·····A··renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_time=1hour |
3410 | ·························RekeyLimit·1G·1hour······································································potential·attacks | 3410 | ·························RekeyLimit·1G·1hour······································································potential·attacks |
3411 | ··················································································································against·encryption | 3411 | ··················································································································against·encryption |
3412 | ··················································································································keys·are·limited. | 3412 | ··················································································································keys·are·limited. |
3413 | ··················································································································SSH·implementation | 3413 | ··················································································································SSH·implementation |
3414 | ··················································································································in·Oracle·Linux·8 | 3414 | ··················································································································in·Oracle·Linux·8 |
3415 | ··················································································································uses·the·openssl | 3415 | ··················································································································uses·the·openssl |
3416 | ··················································································································library,·which | 3416 | ··················································································································library,·which |
Offset 4075, 15 lines modified | Offset 4075, 15 lines modified | ||
4075 | <tt>RekeyLimit</tt>. | 4075 | <tt>RekeyLimit</tt>. |
4076 | ··</td> | 4076 | ··</td> |
4077 | ··<td·xml:lang="en-US"> | 4077 | ··<td·xml:lang="en-US"> |
4078 | By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling | 4078 | By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling |
4079 | time-based·limit,·effects·of·potential·attacks·against | 4079 | time-based·limit,·effects·of·potential·attacks·against |
4080 | encryption·keys·are·limited. | 4080 | encryption·keys·are·limited. |
4081 | ··</td> | 4081 | ··</td> |
4082 | ··<td>var_ssh_client_rekey_limit_ | 4082 | ··<td>var_ssh_client_rekey_limit_time=1hour<br/>var_ssh_client_rekey_limit_size=1G</td> |
4083 | </tr> | 4083 | </tr> |
4084 | <tr> | 4084 | <tr> |
4085 | ··<td></td> | 4085 | ··<td></td> |
4086 | ··<td>CCE-83349-1</td> | 4086 | ··<td>CCE-83349-1</td> |
4087 | ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td> | 4087 | ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td> |
4088 | ··<td·xml:lang="en-US"> | 4088 | ··<td·xml:lang="en-US"> |
4089 | To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure | 4089 | To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure |
Offset 4138, 15 lines modified | Offset 4138, 15 lines modified | ||
4138 | <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre> | 4138 | <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre> |
4139 | ··</td> | 4139 | ··</td> |
4140 | ··<td·xml:lang="en-US"> | 4140 | ··<td·xml:lang="en-US"> |
4141 | By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling | 4141 | By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling |
4142 | time-based·limit,·effects·of·potential·attacks·against | 4142 | time-based·limit,·effects·of·potential·attacks·against |
4143 | encryption·keys·are·limited. | 4143 | encryption·keys·are·limited. |
4144 | ··</td> | 4144 | ··</td> |
4145 | ··<td>var_rekey_limit_ | 4145 | ··<td>var_rekey_limit_size=1G<br/>var_rekey_limit_time=1hour</td> |
4146 | </tr> | 4146 | </tr> |
4147 | <tr> | 4147 | <tr> |
4148 | ··<td></td> | 4148 | ··<td></td> |
4149 | ··<td>CCE-82462-3</td> | 4149 | ··<td>CCE-82462-3</td> |
4150 | ··<td>SSH·server·uses·strong·entropy·to·seed</td> | 4150 | ··<td>SSH·server·uses·strong·entropy·to·seed</td> |
4151 | ··<td·xml:lang="en-US"> | 4151 | ··<td·xml:lang="en-US"> |
4152 | To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file. | 4152 | To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file. |
Offset 3356, 16 lines modified | Offset 3356, 16 lines modified | ||
3356 | ······················································································································options,·which·can | 3356 | ······················································································································options,·which·can |
3357 | ······················································································································help·protect | 3357 | ······················································································································help·protect |
3358 | ······················································································································programs·which·use | 3358 | ······················································································································programs·which·use |
3359 | ······················································································································it. | 3359 | ······················································································································it. |
3360 | ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the | 3360 | ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the |
3361 | ·····························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the | 3361 | ·····························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the |
3362 | ·····CCE-···Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and | 3362 | ·····CCE-···Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and |
3363 | ·····82880-·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_ | 3363 | ·····82880-·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_time=1hour |
3364 | ·····6······renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_ | 3364 | ·····6······renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_size=1G |
3365 | ············for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks | 3365 | ············for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks |
3366 | ·····························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption | 3366 | ·····························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption |
3367 | ·····························containing·definition·of·RekeyLimit.·····················································keys·are·limited. | 3367 | ·····························containing·definition·of·RekeyLimit.·····················································keys·are·limited. |
3368 | ······················································································································Some·SSH | 3368 | ······················································································································Some·SSH |
3369 | ······················································································································implementations·use | 3369 | ······················································································································implementations·use |
3370 | ······················································································································the·openssl·library | 3370 | ······················································································································the·openssl·library |
3371 | ······················································································································for·entropy,·which | 3371 | ······················································································································for·entropy,·which |
Offset 3416, 16 lines modified | Offset 3416, 16 lines modified | ||
3416 | ······················································································································generator·used·by | 3416 | ······················································································································generator·used·by |
3417 | ······················································································································SSH·would·be·known | 3417 | ······················································································································SSH·would·be·known |
3418 | ······················································································································to·potential | 3418 | ······················································································································to·potential |
3419 | ······················································································································attackers. | 3419 | ······················································································································attackers. |
3420 | ······················································································································By·decreasing·the | 3420 | ······················································································································By·decreasing·the |
3421 | ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the | 3421 | ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the |
3422 | ·····CCE-···Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and | 3422 | ·····CCE-···Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and |
3423 | ·····82177-·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_ | 3423 | ·····82177-·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_size=1G |
3424 | ·····7······renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_ | 3424 | ·····7······renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_time=1hour |
3425 | ·····························RekeyLimit·1G·1hour······································································potential·attacks | 3425 | ·····························RekeyLimit·1G·1hour······································································potential·attacks |
3426 | ······················································································································against·encryption | 3426 | ······················································································································against·encryption |
3427 | ······················································································································keys·are·limited. | 3427 | ······················································································································keys·are·limited. |
3428 | ······················································································································SSH·implementation | 3428 | ······················································································································SSH·implementation |
3429 | ······················································································································in·Red·Hat | 3429 | ······················································································································in·Red·Hat |
3430 | ······················································································································Enterprise·Linux·8 | 3430 | ······················································································································Enterprise·Linux·8 |
3431 | ······················································································································uses·the·openssl | 3431 | ······················································································································uses·the·openssl |
Offset 1, 10 lines modified | Offset 1, 10 lines modified | ||
1 | <?xml·version="1.0"·encoding="utf-8"?> | 1 | <?xml·version="1.0"·encoding="utf-8"?> |
2 | <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default"> | 2 | <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default"> |
3 | ··<xccdf-1.2:version·time="2025-0 | 3 | ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version> |
4 | ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig"> | 4 | ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig"> |
5 | ····<xccdf-1.2:title·override="true">DISA·STIG·for·Oracle·Linux·8</xccdf-1.2:title> | 5 | ····<xccdf-1.2:title·override="true">DISA·STIG·for·Oracle·Linux·8</xccdf-1.2:title> |
6 | ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the | 6 | ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the |
7 | DISA·STIG·for·Oracle·Linux·8·V2R3.</xccdf-1.2:description> | 7 | DISA·STIG·for·Oracle·Linux·8·V2R3.</xccdf-1.2:description> |
8 | ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs"·selected="false"/> | 8 | ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs"·selected="false"/> |
9 | ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay"·selected="false"/> | 9 | ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay"·selected="false"/> |
10 | ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions"·selected="false"/> | 10 | ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions"·selected="false"/> |
Offset 1, 10 lines modified | Offset 1, 10 lines modified | ||
1 | <?xml·version="1.0"·encoding="utf-8"?> | 1 | <?xml·version="1.0"·encoding="utf-8"?> |
2 | <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default"> | 2 | <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default"> |
3 | ··<xccdf-1.2:version·time="2025-0 | 3 | ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version> |
4 | ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig"> | 4 | ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig"> |
5 | ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title> | 5 | ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title> |
6 | ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the | 6 | ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the |
7 | DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V2R2. | 7 | DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V2R2. |
8 | In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·this | 8 | In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·this |
9 | configuration·baseline·is·applicable·to·the·operating·system·tier·of | 9 | configuration·baseline·is·applicable·to·the·operating·system·tier·of |
Offset 1, 10 lines modified | Offset 1, 10 lines modified | ||
1 | <?xml·version="1.0"·encoding="utf-8"?> | 1 | <?xml·version="1.0"·encoding="utf-8"?> |
2 | <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default"> | 2 | <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default"> |
3 | ··<xccdf-1.2:version·time="2025-0 | 3 | ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version> |
4 | ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig"> | 4 | ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig"> |
5 | ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title> | 5 | ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title> |
6 | ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the | 6 | ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the |
7 | DISA·STIG·for·Red·Hat·Enterprise·Linux·9·V2R3. | 7 | DISA·STIG·for·Red·Hat·Enterprise·Linux·9·V2R3. |
8 | In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·9,·this | 8 | In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·9,·this |
9 | configuration·baseline·is·applicable·to·the·operating·system·tier·of | 9 | configuration·baseline·is·applicable·to·the·operating·system·tier·of |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:amazon:amazon_linux:2023"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:amazon:amazon_linux:2023"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Amazon·Linux·2023</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Amazon·Linux·2023</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml">oval:ssg-installed_OS_is_al2023:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml">oval:ssg-installed_OS_is_al2023:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_AL-2023"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_AL-2023"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Linux·2023</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Linux·2023</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Amazon·Linux·2023.·It·is·a·rendering·of | 40 | configuration·settings·for·Amazon·Linux·2023.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 98811, 15 lines modified | Offset 98811, 15 lines modified | ||
98811 | ··············<xccdf-1.2:check-content-ref·href="ssg-al2023-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/> | 98811 | ··············<xccdf-1.2:check-content-ref·href="ssg-al2023-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/> |
98812 | ············</xccdf-1.2:check> | 98812 | ············</xccdf-1.2:check> |
98813 | ··········</xccdf-1.2:Rule> | 98813 | ··········</xccdf-1.2:Rule> |
98814 | ········</xccdf-1.2:Group> | 98814 | ········</xccdf-1.2:Group> |
98815 | ······</xccdf-1.2:Group> | 98815 | ······</xccdf-1.2:Group> |
98816 | ····</xccdf-1.2:Benchmark> | 98816 | ····</xccdf-1.2:Benchmark> |
98817 | ··</ds:component> | 98817 | ··</ds:component> |
98818 | ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-oval.xml"·timestamp="2025-0 | 98818 | ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-oval.xml"·timestamp="2025-03-01T22:08:00"> |
98819 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 98819 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
98820 | ······<oval-def:generator> | 98820 | ······<oval-def:generator> |
98821 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 98821 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
98822 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 98822 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
98823 | ········<oval:schema_version>5.11</oval:schema_version> | 98823 | ········<oval:schema_version>5.11</oval:schema_version> |
98824 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 98824 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
98825 | ······</oval-def:generator> | 98825 | ······</oval-def:generator> |
Offset 117150, 3096 lines modified | Offset 117150, 3096 lines modified | ||
117150 | ············</oval-def:arithmetic> | 117150 | ············</oval-def:arithmetic> |
117151 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 117151 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
117152 | ··········</oval-def:arithmetic> | 117152 | ··········</oval-def:arithmetic> |
117153 | ········</oval-def:local_variable> | 117153 | ········</oval-def:local_variable> |
117154 | ······</oval-def:variables> | 117154 | ······</oval-def:variables> |
117155 | ····</oval-def:oval_definitions> | 117155 | ····</oval-def:oval_definitions> |
117156 | ··</ds:component> | 117156 | ··</ds:component> |
117157 | ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-ocil.xml"·timestamp="2025-0 | 117157 | ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
117158 | ····<ocil:ocil> | 117158 | ····<ocil:ocil> |
117159 | ······<ocil:generator> | 117159 | ······<ocil:generator> |
117160 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 117160 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
117161 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 117161 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
117162 | ········<ocil:schema_version>2.0</ocil:schema_version> | 117162 | ········<ocil:schema_version>2.0</ocil:schema_version> |
117163 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 117163 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
117164 | ······</ocil:generator> | 117164 | ······</ocil:generator> |
117165 | ······<ocil:questionnaires> | 117165 | ······<ocil:questionnaires> |
117166 | ········<ocil:questionnaire·id="ocil:ssg- | 117166 | ········<ocil:questionnaire·id="ocil:ssg-accounts_set_post_pw_existing_ocil:questionnaire:1"> |
117167 | ··········<ocil:title>Set·existing·passwords·a·period·of·inactivity·before·they·been·locked</ocil:title> | ||
117167 | ··········<ocil:title>Set·Password·Hashing·Algorithm·in·/etc/login.defs</ocil:title> | ||
117168 | ··········<ocil:actions> | ||
117169 | ············<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_logindefs_action:testaction:1</ocil:test_action_ref> | ||
117170 | ··········</ocil:actions> | ||
117171 | ········</ocil:questionnaire> | ||
117172 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1"> | ||
117173 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title> | ||
117174 | ··········<ocil:actions> | 117168 | ··········<ocil:actions> |
117175 | ············<ocil:test_action_ref>ocil:ssg-a | 117169 | ············<ocil:test_action_ref>ocil:ssg-accounts_set_post_pw_existing_action:testaction:1</ocil:test_action_ref> |
117176 | ··········</ocil:actions> | 117170 | ··········</ocil:actions> |
117177 | ········</ocil:questionnaire> | 117171 | ········</ocil:questionnaire> |
117178 | ········<ocil:questionnaire·id="ocil:ssg-file_ | 117172 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_home_directories_ocil:questionnaire:1"> |
117179 | ··········<ocil:title> | 117173 | ··········<ocil:title>All·Interactive·User·Home·Directories·Must·Have·mode·0750·Or·Less·Permissive</ocil:title> |
117180 | ··········<ocil:actions> | 117174 | ··········<ocil:actions> |
117181 | ············<ocil:test_action_ref>ocil:ssg-file_ | 117175 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_home_directories_action:testaction:1</ocil:test_action_ref> |
117182 | ··········</ocil:actions> | 117176 | ··········</ocil:actions> |
117183 | ········</ocil:questionnaire> | 117177 | ········</ocil:questionnaire> |
117184 | ········<ocil:questionnaire·id="ocil:ssg- | 117178 | ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1"> |
117185 | ··········<ocil:title>Ensure· | 117179 | ··········<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title> |
117186 | ··········<ocil:actions> | 117180 | ··········<ocil:actions> |
117187 | ············<ocil:test_action_ref>ocil:ssg- | 117181 | ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref> |
117188 | ··········</ocil:actions> | 117182 | ··········</ocil:actions> |
117189 | ········</ocil:questionnaire> | 117183 | ········</ocil:questionnaire> |
117190 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1"> | ||
117191 | ········ | 117184 | ········<ocil:questionnaire·id="ocil:ssg-package_cyrus-imapd_removed_ocil:questionnaire:1"> |
117185 | ··········<ocil:title>Uninstall·cyrus-imapd·Package</ocil:title> | ||
117192 | ··········<ocil:actions> | 117186 | ··········<ocil:actions> |
117193 | ············<ocil:test_action_ref>ocil:ssg- | 117187 | ············<ocil:test_action_ref>ocil:ssg-package_cyrus-imapd_removed_action:testaction:1</ocil:test_action_ref> |
117194 | ··········</ocil:actions> | 117188 | ··········</ocil:actions> |
117195 | ········</ocil:questionnaire> | 117189 | ········</ocil:questionnaire> |
117196 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1"> | ||
117197 | ········ | 117190 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1"> |
117191 | ··········<ocil:title>Verify·Group·Ownership·of·Message·of·the·Day·Banner</ocil:title> | ||
117198 | ··········<ocil:actions> | 117192 | ··········<ocil:actions> |
117199 | ············<ocil:test_action_ref>ocil:ssg- | 117193 | ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref> |
117200 | ··········</ocil:actions> | 117194 | ··········</ocil:actions> |
117201 | ········</ocil:questionnaire> | 117195 | ········</ocil:questionnaire> |
117202 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 117196 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_shadow_ocil:questionnaire:1"> |
117203 | ··········<ocil:title> | 117197 | ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/shadow</ocil:title> |
117204 | ··········<ocil:actions> | 117198 | ··········<ocil:actions> |
117205 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_ | 117199 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_shadow_action:testaction:1</ocil:test_action_ref> |
117206 | ··········</ocil:actions> | 117200 | ··········</ocil:actions> |
117207 | ········</ocil:questionnaire> | 117201 | ········</ocil:questionnaire> |
117208 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1"> | ||
117209 | ········ | 117202 | ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1"> |
117203 | ··········<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title> | ||
117210 | ··········<ocil:actions> | 117204 | ··········<ocil:actions> |
117211 | ············<ocil:test_action_ref>ocil:ssg-s | 117205 | ············<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref> |
117212 | ··········</ocil:actions> | 117206 | ··········</ocil:actions> |
117213 | ········</ocil:questionnaire> | 117207 | ········</ocil:questionnaire> |
117214 | ········<ocil:questionnaire·id="ocil:ssg- | 117208 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1"> |
117215 | ··········<ocil:title> | 117209 | ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title> |
117216 | ··········<ocil:actions> | 117210 | ··········<ocil:actions> |
117217 | ············<ocil:test_action_ref>ocil:ssg- | 117211 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref> |
117218 | ··········</ocil:actions> | 117212 | ··········</ocil:actions> |
117219 | ········</ocil:questionnaire> | 117213 | ········</ocil:questionnaire> |
117220 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_d_ocil:questionnaire:1"> | ||
117221 | ········· | 117214 | ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_admin_space_left_action_ocil:questionnaire:1"> |
117215 | ··········<ocil:title>Configure·auditd·admin_space_left·Action·on·Low·Disk·Space</ocil:title> | ||
117222 | ··········<ocil:actions> | 117216 | ··········<ocil:actions> |
117223 | ············<ocil:test_action_ref>ocil:ssg- | 117217 | ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_admin_space_left_action_action:testaction:1</ocil:test_action_ref> |
117224 | ··········</ocil:actions> | 117218 | ··········</ocil:actions> |
117225 | ········</ocil:questionnaire> | 117219 | ········</ocil:questionnaire> |
117226 | ········<ocil:questionnaire·id="ocil:ssg- | 117220 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1"> |
117227 | ··········<ocil:title> | 117221 | ··········<ocil:title>Verify·Group·Who·Owns·cron.hourly</ocil:title> |
117228 | ··········<ocil:actions> | 117222 | ··········<ocil:actions> |
117229 | ············<ocil:test_action_ref>ocil:ssg- | 117223 | ············<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref> |
117230 | ··········</ocil:actions> | 117224 | ··········</ocil:actions> |
117231 | ········</ocil:questionnaire> | 117225 | ········</ocil:questionnaire> |
Max diff block lines reached; 760968/773083 bytes (98.43%) of diff not shown. |
Offset 3, 3087 lines modified | Offset 3, 3087 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-accounts_set_post_pw_existing_ocil:questionnaire:1"> | ||
11 | ······<ocil:title>Set·existing·passwords·a·period·of·inactivity·before·they·been·locked</ocil:title> | ||
10 | ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_logindefs_ocil:questionnaire:1"> | ||
11 | ······<ocil:title>Set·Password·Hashing·Algorithm·in·/etc/login.defs</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_logindefs_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1"> | ||
17 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title> | ||
18 | ······<ocil:actions> | 12 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg-a | 13 | ········<ocil:test_action_ref>ocil:ssg-accounts_set_post_pw_existing_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 14 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg-file_ | 16 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_home_directories_ocil:questionnaire:1"> |
23 | ······<ocil:title> | 17 | ······<ocil:title>All·Interactive·User·Home·Directories·Must·Have·mode·0750·Or·Less·Permissive</ocil:title> |
24 | ······<ocil:actions> | 18 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg-file_ | 19 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_home_directories_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 20 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1"> |
29 | ······<ocil:title>Ensure· | 23 | ······<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title> |
30 | ······<ocil:actions> | 24 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 26 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1"> | ||
35 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-package_cyrus-imapd_removed_ocil:questionnaire:1"> |
29 | ······<ocil:title>Uninstall·cyrus-imapd·Package</ocil:title> | ||
36 | ······<ocil:actions> | 30 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-package_cyrus-imapd_removed_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 32 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1"> | ||
41 | ···· | 34 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1"> |
35 | ······<ocil:title>Verify·Group·Ownership·of·Message·of·the·Day·Banner</ocil:title> | ||
42 | ······<ocil:actions> | 36 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 38 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 40 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_shadow_ocil:questionnaire:1"> |
47 | ······<ocil:title> | 41 | ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/shadow</ocil:title> |
48 | ······<ocil:actions> | 42 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_ | 43 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_shadow_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 44 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1"> | ||
53 | ···· | 46 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1"> |
47 | ······<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title> | ||
54 | ······<ocil:actions> | 48 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg-s | 49 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 50 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg- | 52 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 53 | ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title> |
60 | ······<ocil:actions> | 54 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 56 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_d_ocil:questionnaire:1"> | ||
65 | ····· | 58 | ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_admin_space_left_action_ocil:questionnaire:1"> |
59 | ······<ocil:title>Configure·auditd·admin_space_left·Action·on·Low·Disk·Space</ocil:title> | ||
66 | ······<ocil:actions> | 60 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_admin_space_left_action_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 62 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 65 | ······<ocil:title>Verify·Group·Who·Owns·cron.hourly</ocil:title> |
72 | ······<ocil:actions> | 66 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 68 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1"> | ||
77 | ···· | 70 | ····<ocil:questionnaire·id="ocil:ssg-sudo_require_reauthentication_ocil:questionnaire:1"> |
71 | ······<ocil:title>Require·Re-Authentication·When·Using·the·sudo·Command</ocil:title> | ||
78 | ······<ocil:actions> | 72 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-sudo_require_reauthentication_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 74 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-a | 76 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1"> |
83 | ······<ocil:title>Ens | 77 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title> |
84 | ······<ocil:actions> | 78 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg-a | 79 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 80 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1"> | ||
89 | ···· | 82 | ····<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1"> |
83 | ······<ocil:title>Ensure·LDAP·client·is·not·installed</ocil:title> | ||
90 | ······<ocil:actions> | 84 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-package_openldap-clients_removed_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 86 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg- | 88 | ····<ocil:questionnaire·id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 89 | ······<ocil:title>Set·SSH·Client·Alive·Interval</ocil:title> |
96 | ······<ocil:actions> | 90 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-sshd_set_idle_timeout_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 92 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg- | 94 | ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1"> |
101 | ······<ocil:title> | 95 | ······<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title> |
102 | ······<ocil:actions> | 96 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 98 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 101 | ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv4·Interfaces</ocil:title> |
108 | ······<ocil:actions> | 102 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 104 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg- | 106 | ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_net_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 107 | ······<ocil:title>Modify·the·System·Login·Banner·for·Remote·Connections</ocil:title> |
114 | ······<ocil:actions> | 108 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_net_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 110 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg- | 112 | ····<ocil:questionnaire·id="ocil:ssg-aide_check_audit_tools_ocil:questionnaire:1"> |
119 | ······<ocil:title> | 113 | ······<ocil:title>Configure·AIDE·to·Verify·the·Audit·Tools</ocil:title> |
120 | ······<ocil:actions> | 114 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-aide_check_audit_tools_action:testaction:1</ocil:test_action_ref> |
Max diff block lines reached; 723722/736089 bytes (98.32%) of diff not shown. |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:2"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:2"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·2</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·2</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml">oval:ssg-installed_OS_is_alinux2:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml">oval:ssg-installed_OS_is_alinux2:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-2"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-2"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·2</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·2</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Alibaba·Cloud·Linux·2.·It·is·a·rendering·of | 40 | configuration·settings·for·Alibaba·Cloud·Linux·2.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 58534, 15 lines modified | Offset 58534, 15 lines modified | ||
58534 | ··············<xccdf-1.2:check-content-ref·href="ssg-alinux2-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> | 58534 | ··············<xccdf-1.2:check-content-ref·href="ssg-alinux2-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> |
58535 | ············</xccdf-1.2:check> | 58535 | ············</xccdf-1.2:check> |
58536 | ··········</xccdf-1.2:Rule> | 58536 | ··········</xccdf-1.2:Rule> |
58537 | ········</xccdf-1.2:Group> | 58537 | ········</xccdf-1.2:Group> |
58538 | ······</xccdf-1.2:Group> | 58538 | ······</xccdf-1.2:Group> |
58539 | ····</xccdf-1.2:Benchmark> | 58539 | ····</xccdf-1.2:Benchmark> |
58540 | ··</ds:component> | 58540 | ··</ds:component> |
58541 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-oval.xml"·timestamp="2025-0 | 58541 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-oval.xml"·timestamp="2025-03-01T22:08:00"> |
58542 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 58542 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
58543 | ······<oval-def:generator> | 58543 | ······<oval-def:generator> |
58544 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 58544 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
58545 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 58545 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
58546 | ········<oval:schema_version>5.11</oval:schema_version> | 58546 | ········<oval:schema_version>5.11</oval:schema_version> |
58547 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 58547 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
58548 | ······</oval-def:generator> | 58548 | ······</oval-def:generator> |
Offset 79715, 5616 lines modified | Offset 79715, 5616 lines modified | ||
79715 | ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/> | 79715 | ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/> |
79716 | ··········</oval-def:regex_capture> | 79716 | ··········</oval-def:regex_capture> |
79717 | ········</oval-def:local_variable> | 79717 | ········</oval-def:local_variable> |
79718 | ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/> | 79718 | ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/> |
79719 | ······</oval-def:variables> | 79719 | ······</oval-def:variables> |
79720 | ····</oval-def:oval_definitions> | 79720 | ····</oval-def:oval_definitions> |
79721 | ··</ds:component> | 79721 | ··</ds:component> |
79722 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-ocil.xml"·timestamp="2025-0 | 79722 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
79723 | ····<ocil:ocil> | 79723 | ····<ocil:ocil> |
79724 | ······<ocil:generator> | 79724 | ······<ocil:generator> |
79725 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 79725 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
79726 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 79726 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
79727 | ········<ocil:schema_version>2.0</ocil:schema_version> | 79727 | ········<ocil:schema_version>2.0</ocil:schema_version> |
79728 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 79728 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
79729 | ······</ocil:generator> | 79729 | ······</ocil:generator> |
79730 | ······<ocil:questionnaires> | 79730 | ······<ocil:questionnaires> |
79731 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> | ||
79732 | ··········<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title> | ||
79733 | ··········<ocil:actions> | ||
79734 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref> | ||
79735 | ··········</ocil:actions> | ||
79736 | ········</ocil:questionnaire> | ||
79737 | ········<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1"> | ||
79738 | ··········<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title> | ||
79739 | ··········<ocil:actions> | ||
79740 | ············<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref> | ||
79741 | ··········</ocil:actions> | ||
79742 | ········</ocil:questionnaire> | ||
79743 | ········<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1"> | ||
79744 | ··········<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title> | ||
79745 | ··········<ocil:actions> | ||
79746 | ············<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref> | ||
79747 | ··········</ocil:actions> | ||
79748 | ········</ocil:questionnaire> | ||
79749 | ········<ocil:questionnaire·id="ocil:ssg- | 79731 | ········<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1"> |
79750 | ··········<ocil:title> | 79732 | ··········<ocil:title>Ensure·/dev/shm·is·configured</ocil:title> |
79751 | ··········<ocil:actions> | 79733 | ··········<ocil:actions> |
79752 | ············<ocil:test_action_ref>ocil:ssg- | 79734 | ············<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref> |
79753 | ··········</ocil:actions> | 79735 | ··········</ocil:actions> |
79754 | ········</ocil:questionnaire> | 79736 | ········</ocil:questionnaire> |
79755 | ········<ocil:questionnaire·id="ocil:ssg- | 79737 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1"> |
79756 | ··········<ocil:title> | 79738 | ··········<ocil:title>Enable·automatic·signing·of·all·modules</ocil:title> |
79757 | ··········<ocil:actions> | 79739 | ··········<ocil:actions> |
79758 | ············<ocil:test_action_ref>ocil:ssg- | 79740 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_all_action:testaction:1</ocil:test_action_ref> |
79759 | ··········</ocil:actions> | 79741 | ··········</ocil:actions> |
79760 | ········</ocil:questionnaire> | 79742 | ········</ocil:questionnaire> |
79761 | ········<ocil:questionnaire·id="ocil:ssg-ac | 79743 | ········<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1"> |
79762 | ··········<ocil:title>Ensure· | 79744 | ··········<ocil:title>Ensure·logrotate·is·Installed</ocil:title> |
79763 | ··········<ocil:actions> | 79745 | ··········<ocil:actions> |
79764 | ············<ocil:test_action_ref>ocil:ssg-ac | 79746 | ············<ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref> |
79765 | ··········</ocil:actions> | 79747 | ··········</ocil:actions> |
79766 | ········</ocil:questionnaire> | 79748 | ········</ocil:questionnaire> |
79767 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1"> | ||
79768 | ········ | 79749 | ········<ocil:questionnaire·id="ocil:ssg-service_ip6tables_enabled_ocil:questionnaire:1"> |
79750 | ··········<ocil:title>Verify·ip6tables·Enabled·if·Using·IPv6</ocil:title> | ||
79769 | ··········<ocil:actions> | 79751 | ··········<ocil:actions> |
79770 | ············<ocil:test_action_ref>ocil:ssg- | 79752 | ············<ocil:test_action_ref>ocil:ssg-service_ip6tables_enabled_action:testaction:1</ocil:test_action_ref> |
79771 | ··········</ocil:actions> | 79753 | ··········</ocil:actions> |
79772 | ········</ocil:questionnaire> | 79754 | ········</ocil:questionnaire> |
79773 | ········<ocil:questionnaire·id="ocil:ssg- | 79755 | ········<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1"> |
79774 | ··········<ocil:title> | 79756 | ··········<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title> |
79775 | ··········<ocil:actions> | 79757 | ··········<ocil:actions> |
79776 | ············<ocil:test_action_ref>ocil:ssg- | 79758 | ············<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref> |
79777 | ··········</ocil:actions> | 79759 | ··········</ocil:actions> |
79778 | ········</ocil:questionnaire> | 79760 | ········</ocil:questionnaire> |
79779 | ········<ocil:questionnaire·id="ocil:ssg-s | 79761 | ········<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1"> |
79780 | ··········<ocil:title>Enable· | 79762 | ··········<ocil:title>Enable·cron·Service</ocil:title> |
79781 | ··········<ocil:actions> | 79763 | ··········<ocil:actions> |
79782 | ············<ocil:test_action_ref>ocil:ssg-s | 79764 | ············<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref> |
79783 | ··········</ocil:actions> | 79765 | ··········</ocil:actions> |
79784 | ········</ocil:questionnaire> | 79766 | ········</ocil:questionnaire> |
79785 | ········<ocil:questionnaire·id="ocil:ssg- | 79767 | ········<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1"> |
79786 | ··········<ocil:title>Ensure· | 79768 | ··········<ocil:title>Ensure·gpgcheck·Enabled·In·Main·yum·Configuration</ocil:title> |
79787 | ··········<ocil:actions> | 79769 | ··········<ocil:actions> |
79788 | ············<ocil:test_action_ref>ocil:ssg- | 79770 | ············<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref> |
79789 | ··········</ocil:actions> | 79771 | ··········</ocil:actions> |
79790 | ········</ocil:questionnaire> | 79772 | ········</ocil:questionnaire> |
79791 | ········<ocil:questionnaire·id="ocil:ssg-s | 79773 | ········<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1"> |
79792 | ··········<ocil:title> | 79774 | ··········<ocil:title>Enable·auditd·Service</ocil:title> |
79793 | ··········<ocil:actions> | 79775 | ··········<ocil:actions> |
79794 | ············<ocil:test_action_ref>ocil:ssg-s | 79776 | ············<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref> |
79795 | ··········</ocil:actions> | 79777 | ··········</ocil:actions> |
79796 | ········</ocil:questionnaire> | 79778 | ········</ocil:questionnaire> |
79797 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_ocil:questionnaire:1"> | ||
79798 | ········ | 79779 | ········<ocil:questionnaire·id="ocil:ssg-rpm_verify_permissions_ocil:questionnaire:1"> |
79780 | ··········<ocil:title>Verify·and·Correct·File·Permissions·with·RPM</ocil:title> | ||
79799 | ··········<ocil:actions> | 79781 | ··········<ocil:actions> |
Max diff block lines reached; 907063/918538 bytes (98.75%) of diff not shown. |
Offset 3, 5607 lines modified | Offset 3, 5607 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> | ||
11 | ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1"> | ||
17 | ······<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title> | ||
18 | ······<ocil:actions> | ||
19 | ········<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref> | ||
20 | ······</ocil:actions> | ||
21 | ····</ocil:questionnaire> | ||
22 | ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1"> | ||
23 | ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title> | ||
24 | ······<ocil:actions> | ||
25 | ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref> | ||
26 | ······</ocil:actions> | ||
27 | ····</ocil:questionnaire> | ||
28 | ····<ocil:questionnaire·id="ocil:ssg- | 10 | ····<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1"> |
29 | ······<ocil:title> | 11 | ······<ocil:title>Ensure·/dev/shm·is·configured</ocil:title> |
30 | ······<ocil:actions> | 12 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 14 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg- | 16 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1"> |
35 | ······<ocil:title> | 17 | ······<ocil:title>Enable·automatic·signing·of·all·modules</ocil:title> |
36 | ······<ocil:actions> | 18 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_all_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 20 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-ac | 22 | ····<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1"> |
41 | ······<ocil:title>Ensure· | 23 | ······<ocil:title>Ensure·logrotate·is·Installed</ocil:title> |
42 | ······<ocil:actions> | 24 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg-ac | 25 | ········<ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 26 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1"> | ||
47 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-service_ip6tables_enabled_ocil:questionnaire:1"> |
29 | ······<ocil:title>Verify·ip6tables·Enabled·if·Using·IPv6</ocil:title> | ||
48 | ······<ocil:actions> | 30 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-service_ip6tables_enabled_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 32 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 35 | ······<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title> |
54 | ······<ocil:actions> | 36 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 38 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-s | 40 | ····<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1"> |
59 | ······<ocil:title>Enable· | 41 | ······<ocil:title>Enable·cron·Service</ocil:title> |
60 | ······<ocil:actions> | 42 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg-s | 43 | ········<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 44 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1"> | ||
65 | ···· | 46 | ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1"> |
47 | ······<ocil:title>Ensure·gpgcheck·Enabled·In·Main·yum·Configuration</ocil:title> | ||
66 | ······<ocil:actions> | 48 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 50 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg-s | 52 | ····<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 53 | ······<ocil:title>Enable·auditd·Service</ocil:title> |
72 | ······<ocil:actions> | 54 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg-s | 55 | ········<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 56 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_ocil:questionnaire:1"> | ||
77 | ···· | 58 | ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_permissions_ocil:questionnaire:1"> |
59 | ······<ocil:title>Verify·and·Correct·File·Permissions·with·RPM</ocil:title> | ||
78 | ······<ocil:actions> | 60 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-rpm_verify_permissions_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 62 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-co | 64 | ····<ocil:questionnaire·id="ocil:ssg-coredump_disable_storage_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 65 | ······<ocil:title>Disable·storing·core·dump</ocil:title> |
84 | ······<ocil:actions> | 66 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg-co | 67 | ········<ocil:test_action_ref>ocil:ssg-coredump_disable_storage_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 68 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 71 | ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title> |
90 | ······<ocil:actions> | 72 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 74 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-sshd_s | 76 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 77 | ······<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title> |
96 | ······<ocil:actions> | 78 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg-sshd_s | 79 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 80 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg- | 82 | ····<ocil:questionnaire·id="ocil:ssg-ensure_logrotate_activated_ocil:questionnaire:1"> |
101 | ······<ocil:title>En | 83 | ······<ocil:title>Ensure·Logrotate·Runs·Periodically</ocil:title> |
102 | ······<ocil:actions> | 84 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-ensure_logrotate_activated_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 86 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_clock_settime_ocil:questionnaire:1"> | ||
107 | ···· | 88 | ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1"> |
89 | ······<ocil:title>System·Audit·Logs·Must·Have·Mode·0750·or·Less·Permissive</ocil:title> | ||
108 | ······<ocil:actions> | 90 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 92 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg- | 94 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 95 | ······<ocil:title>Disable·SSH·root·Login·with·a·Password·(Insecure)</ocil:title> |
114 | ······<ocil:actions> | 96 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 98 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1"> | ||
119 | ···· | 100 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1"> |
101 | ······<ocil:title>Disable·Kerberos·Authentication</ocil:title> | ||
120 | ······<ocil:actions> | 102 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 104 | ······</ocil:actions> |
123 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
124 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ocil:questionnaire:1"> | ||
Max diff block lines reached; 863595/875423 bytes (98.65%) of diff not shown. |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:3"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:3"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·3</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·3</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml">oval:ssg-installed_OS_is_alinux3:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml">oval:ssg-installed_OS_is_alinux3:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-3"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-3"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·3</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·3</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Alibaba·Cloud·Linux·3.·It·is·a·rendering·of | 40 | configuration·settings·for·Alibaba·Cloud·Linux·3.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 57666, 15 lines modified | Offset 57666, 15 lines modified | ||
57666 | ··············<xccdf-1.2:check-content-ref·href="ssg-alinux3-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> | 57666 | ··············<xccdf-1.2:check-content-ref·href="ssg-alinux3-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> |
57667 | ············</xccdf-1.2:check> | 57667 | ············</xccdf-1.2:check> |
57668 | ··········</xccdf-1.2:Rule> | 57668 | ··········</xccdf-1.2:Rule> |
57669 | ········</xccdf-1.2:Group> | 57669 | ········</xccdf-1.2:Group> |
57670 | ······</xccdf-1.2:Group> | 57670 | ······</xccdf-1.2:Group> |
57671 | ····</xccdf-1.2:Benchmark> | 57671 | ····</xccdf-1.2:Benchmark> |
57672 | ··</ds:component> | 57672 | ··</ds:component> |
57673 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-oval.xml"·timestamp="2025-0 | 57673 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-oval.xml"·timestamp="2025-03-01T22:08:00"> |
57674 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 57674 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
57675 | ······<oval-def:generator> | 57675 | ······<oval-def:generator> |
57676 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 57676 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
57677 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 57677 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
57678 | ········<oval:schema_version>5.11</oval:schema_version> | 57678 | ········<oval:schema_version>5.11</oval:schema_version> |
57679 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 57679 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
57680 | ······</oval-def:generator> | 57680 | ······</oval-def:generator> |
Offset 77997, 5783 lines modified | Offset 77997, 5808 lines modified | ||
77997 | ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/> | 77997 | ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/> |
77998 | ··········</oval-def:regex_capture> | 77998 | ··········</oval-def:regex_capture> |
77999 | ········</oval-def:local_variable> | 77999 | ········</oval-def:local_variable> |
78000 | ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/> | 78000 | ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/> |
78001 | ······</oval-def:variables> | 78001 | ······</oval-def:variables> |
78002 | ····</oval-def:oval_definitions> | 78002 | ····</oval-def:oval_definitions> |
78003 | ··</ds:component> | 78003 | ··</ds:component> |
78004 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-ocil.xml"·timestamp="2025-0 | 78004 | ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
78005 | ····<ocil:ocil> | 78005 | ····<ocil:ocil> |
78006 | ······<ocil:generator> | 78006 | ······<ocil:generator> |
78007 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 78007 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
78008 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 78008 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
78009 | ········<ocil:schema_version>2.0</ocil:schema_version> | 78009 | ········<ocil:schema_version>2.0</ocil:schema_version> |
78010 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 78010 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
78011 | ······</ocil:generator> | 78011 | ······</ocil:generator> |
78012 | ······<ocil:questionnaires> | 78012 | ······<ocil:questionnaires> |
78013 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_ocil:questionnaire:1"> | ||
78014 | ··········<ocil:title>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</ocil:title> | ||
78015 | ··········<ocil:actions> | ||
78016 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_tcp_syncookies_action:testaction:1</ocil:test_action_ref> | ||
78017 | ··········</ocil:actions> | ||
78018 | ········</ocil:questionnaire> | ||
78019 | ········<ocil:questionnaire·id="ocil:ssg- | 78013 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1"> |
78020 | ··········<ocil:title> | 78014 | ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·creat</ocil:title> |
78021 | ··········<ocil:actions> | 78015 | ··········<ocil:actions> |
78022 | ············<ocil:test_action_ref>ocil:ssg- | 78016 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref> |
78023 | ··········</ocil:actions> | 78017 | ··········</ocil:actions> |
78024 | ········</ocil:questionnaire> | 78018 | ········</ocil:questionnaire> |
78025 | ········<ocil:questionnaire·id="ocil:ssg- | 78019 | ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1"> |
78026 | ··········<ocil:title> | 78020 | ··········<ocil:title>Disable·SSH·root·Login·with·a·Password·(Insecure)</ocil:title> |
78027 | ··········<ocil:actions> | 78021 | ··········<ocil:actions> |
78028 | ············<ocil:test_action_ref>ocil:ssg- | 78022 | ············<ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref> |
78029 | ··········</ocil:actions> | 78023 | ··········</ocil:actions> |
78030 | ········</ocil:questionnaire> | 78024 | ········</ocil:questionnaire> |
78031 | ········<ocil:questionnaire·id="ocil:ssg- | 78025 | ········<ocil:questionnaire·id="ocil:ssg-package_ntp_installed_ocil:questionnaire:1"> |
78032 | ··········<ocil:title> | 78026 | ··········<ocil:title>Install·the·ntp·service</ocil:title> |
78033 | ··········<ocil:actions> | 78027 | ··········<ocil:actions> |
78034 | ············<ocil:test_action_ref>ocil:ssg- | 78028 | ············<ocil:test_action_ref>ocil:ssg-package_ntp_installed_action:testaction:1</ocil:test_action_ref> |
78035 | ··········</ocil:actions> | 78029 | ··········</ocil:actions> |
78036 | ········</ocil:questionnaire> | 78030 | ········</ocil:questionnaire> |
78037 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1"> | ||
78038 | ········ | 78031 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_ocil:questionnaire:1"> |
78032 | ··········<ocil:title>Disable·IPv6·Addressing·on·IPv6·Interfaces·by·Default</ocil:title> | ||
78039 | ··········<ocil:actions> | 78033 | ··········<ocil:actions> |
78040 | ············<ocil:test_action_ref>ocil:ssg- | 78034 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_action:testaction:1</ocil:test_action_ref> |
78041 | ··········</ocil:actions> | 78035 | ··········</ocil:actions> |
78042 | ········</ocil:questionnaire> | 78036 | ········</ocil:questionnaire> |
78043 | ········<ocil:questionnaire·id="ocil:ssg- | 78037 | ········<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1"> |
78044 | ··········<ocil:title> | 78038 | ··········<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title> |
78045 | ··········<ocil:actions> | 78039 | ··········<ocil:actions> |
78046 | ············<ocil:test_action_ref>ocil:ssg- | 78040 | ············<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref> |
78047 | ··········</ocil:actions> | 78041 | ··········</ocil:actions> |
78048 | ········</ocil:questionnaire> | 78042 | ········</ocil:questionnaire> |
78049 | ········<ocil:questionnaire·id="ocil:ssg-postfix_network_listening_disabled_ocil:questionnaire:1"> | ||
78050 | ········ | 78043 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1"> |
78044 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmod</ocil:title> | ||
78051 | ··········<ocil:actions> | 78045 | ··········<ocil:actions> |
78052 | ············<ocil:test_action_ref>ocil:ssg- | 78046 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmod_action:testaction:1</ocil:test_action_ref> |
78053 | ··········</ocil:actions> | 78047 | ··········</ocil:actions> |
78054 | ········</ocil:questionnaire> | 78048 | ········</ocil:questionnaire> |
78055 | ········<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1"> | ||
78056 | ········· | 78049 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1"> |
78050 | ··········<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title> | ||
78057 | ··········<ocil:actions> | 78051 | ··········<ocil:actions> |
78058 | ············<ocil:test_action_ref>ocil:ssg- | 78052 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref> |
78059 | ··········</ocil:actions> | 78053 | ··········</ocil:actions> |
78060 | ········</ocil:questionnaire> | 78054 | ········</ocil:questionnaire> |
78061 | ········<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1"> | ||
78062 | ········ | 78055 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1"> |
78056 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title> | ||
78063 | ··········<ocil:actions> | 78057 | ··········<ocil:actions> |
78064 | ············<ocil:test_action_ref>ocil:ssg-a | 78058 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref> |
78065 | ··········</ocil:actions> | 78059 | ··········</ocil:actions> |
78066 | ········</ocil:questionnaire> | 78060 | ········</ocil:questionnaire> |
78067 | ········<ocil:questionnaire·id="ocil:ssg- | 78061 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_group_ocil:questionnaire:1"> |
78068 | ··········<ocil:title> | 78062 | ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/group</ocil:title> |
78069 | ··········<ocil:actions> | 78063 | ··········<ocil:actions> |
78070 | ············<ocil:test_action_ref>ocil:ssg- | 78064 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_group_action:testaction:1</ocil:test_action_ref> |
78071 | ··········</ocil:actions> | 78065 | ··········</ocil:actions> |
78072 | ········</ocil:questionnaire> | 78066 | ········</ocil:questionnaire> |
78073 | ········<ocil:questionnaire·id="ocil:ssg-package_sudo_installed_ocil:questionnaire:1"> | ||
78074 | ········ | 78067 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1"> |
78068 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lsetxattr</ocil:title> | ||
78075 | ··········<ocil:actions> | 78069 | ··········<ocil:actions> |
78076 | ············<ocil:test_action_ref>ocil:ssg- | 78070 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref> |
78077 | ··········</ocil:actions> | 78071 | ··········</ocil:actions> |
78078 | ········</ocil:questionnaire> | 78072 | ········</ocil:questionnaire> |
Max diff block lines reached; 907121/919294 bytes (98.68%) of diff not shown. |
Offset 3, 5774 lines modified | Offset 3, 5799 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_ocil:questionnaire:1"> | ||
11 | ······<ocil:title>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_tcp_syncookies_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg- | 10 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1"> |
17 | ······<ocil:title> | 11 | ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·creat</ocil:title> |
18 | ······<ocil:actions> | 12 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 14 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1"> | ||
23 | ···· | 16 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1"> |
17 | ······<ocil:title>Disable·SSH·root·Login·with·a·Password·(Insecure)</ocil:title> | ||
24 | ······<ocil:actions> | 18 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 20 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-package_ntp_installed_ocil:questionnaire:1"> |
29 | ······<ocil:title> | 23 | ······<ocil:title>Install·the·ntp·service</ocil:title> |
30 | ······<ocil:actions> | 24 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-package_ntp_installed_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 26 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1"> | ||
35 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_ocil:questionnaire:1"> |
29 | ······<ocil:title>Disable·IPv6·Addressing·on·IPv6·Interfaces·by·Default</ocil:title> | ||
36 | ······<ocil:actions> | 30 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 32 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 35 | ······<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title> |
42 | ······<ocil:actions> | 36 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 38 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-postfix_network_listening_disabled_ocil:questionnaire:1"> | ||
47 | ···· | 40 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1"> |
41 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmod</ocil:title> | ||
48 | ······<ocil:actions> | 42 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmod_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 44 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1"> | ||
53 | ····· | 46 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1"> |
47 | ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title> | ||
54 | ······<ocil:actions> | 48 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 50 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1"> | ||
59 | ···· | 52 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1"> |
53 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title> | ||
60 | ······<ocil:actions> | 54 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg-a | 55 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 56 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_group_ocil:questionnaire:1"> |
65 | ······<ocil:title> | 59 | ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/group</ocil:title> |
66 | ······<ocil:actions> | 60 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_group_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 62 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg-package_sudo_installed_ocil:questionnaire:1"> | ||
71 | ···· | 64 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1"> |
65 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lsetxattr</ocil:title> | ||
72 | ······<ocil:actions> | 66 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 68 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_ocil:questionnaire:1"> | ||
77 | ···· | 70 | ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_permissions_ocil:questionnaire:1"> |
71 | ······<ocil:title>Ensure·System·Log·Files·Have·Correct·Permissions</ocil:title> | ||
78 | ······<ocil:actions> | 72 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_permissions_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 74 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg- | 76 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 77 | ······<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title> |
84 | ······<ocil:actions> | 78 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 80 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg- | 82 | ····<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 83 | ······<ocil:title>Install·the·cron·service</ocil:title> |
90 | ······<ocil:actions> | 84 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 86 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1"> | ||
95 | ···· | 88 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1"> |
89 | ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·openat</ocil:title> | ||
96 | ······<ocil:actions> | 90 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 92 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-service_qpidd_disabled_ocil:questionnaire:1"> | 94 | ····<ocil:questionnaire·id="ocil:ssg-service_qpidd_disabled_ocil:questionnaire:1"> |
101 | ······<ocil:title>Disable·Apache·Qpid·(qpidd)</ocil:title> | 95 | ······<ocil:title>Disable·Apache·Qpid·(qpidd)</ocil:title> |
102 | ······<ocil:actions> | 96 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg-service_qpidd_disabled_action:testaction:1</ocil:test_action_ref> | 97 | ········<ocil:test_action_ref>ocil:ssg-service_qpidd_disabled_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 98 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_permissions_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 101 | ······<ocil:title>Verify·and·Correct·File·Permissions·with·RPM</ocil:title> |
108 | ······<ocil:actions> | 102 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-rpm_verify_permissions_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 104 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg- | 106 | ····<ocil:questionnaire·id="ocil:ssg-chronyd_run_as_chrony_user_ocil:questionnaire:1"> |
113 | ······<ocil:title>Ensure· | 107 | ······<ocil:title>Ensure·that·chronyd·is·running·under·chrony·user·account</ocil:title> |
114 | ······<ocil:actions> | 108 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-chronyd_run_as_chrony_user_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 110 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_hourly_ocil:questionnaire:1"> | ||
119 | ···· | 112 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1"> |
113 | ······<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title> | ||
120 | ······<ocil:actions> | 114 | ······<ocil:actions> |
Max diff block lines reached; 864787/876809 bytes (98.63%) of diff not shown. |
Offset 21, 23 lines modified | Offset 21, 23 lines modified | ||
21 | ····<ds:checks> | 21 | ····<ds:checks> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-oval.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-oval.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"/> |
24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-cpe-oval.xml"/> | 24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-cpe-oval.xml"/> |
25 | ······<ds:component-ref·id="scap_org.open-scap_cref_oval-org.almalinux.alsa-9.xml.bz2"·xlink:href="https://security.almalinux.org/oval/org.almalinux.alsa-9.xml.bz2"/> | 25 | ······<ds:component-ref·id="scap_org.open-scap_cref_oval-org.almalinux.alsa-9.xml.bz2"·xlink:href="https://security.almalinux.org/oval/org.almalinux.alsa-9.xml.bz2"/> |
26 | ····</ds:checks> | 26 | ····</ds:checks> |
27 | ··</ds:data-stream> | 27 | ··</ds:data-stream> |
28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-cpe-dictionary.xml"·timestamp="2025-0 | 28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
30 | ······<cpe-dict:cpe-item·name="cpe:/o:almalinux:almalinux:9"> | 30 | ······<cpe-dict:cpe-item·name="cpe:/o:almalinux:almalinux:9"> |
31 | ········<cpe-dict:title·xml:lang="en-us">AlmaLinux·OS·9</cpe-dict:title> | 31 | ········<cpe-dict:title·xml:lang="en-us">AlmaLinux·OS·9</cpe-dict:title> |
32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml">oval:ssg-installed_OS_is_almalinux9:def:1</cpe-dict:check> | 32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml">oval:ssg-installed_OS_is_almalinux9:def:1</cpe-dict:check> |
33 | ······</cpe-dict:cpe-item> | 33 | ······</cpe-dict:cpe-item> |
34 | ····</cpe-dict:cpe-list> | 34 | ····</cpe-dict:cpe-list> |
35 | ··</ds:component> | 35 | ··</ds:component> |
36 | ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-xccdf.xml"·timestamp="2025-0 | 36 | ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
37 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALMALINUX-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 37 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALMALINUX-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
38 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 38 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
39 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·AlmaLinux·OS·9</xccdf-1.2:title> | 39 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·AlmaLinux·OS·9</xccdf-1.2:title> |
40 | ······<xccdf-1.2:description> | 40 | ······<xccdf-1.2:description> |
41 | ········This·guide·presents·a·catalog·of·security-relevant | 41 | ········This·guide·presents·a·catalog·of·security-relevant |
42 | configuration·settings·for·AlmaLinux·OS·9.·It·is·a·rendering·of | 42 | configuration·settings·for·AlmaLinux·OS·9.·It·is·a·rendering·of |
43 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 43 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 131587, 15 lines modified | Offset 131587, 15 lines modified | ||
131587 | ··············<xccdf-1.2:check-content-ref·href="ssg-almalinux9-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/> | 131587 | ··············<xccdf-1.2:check-content-ref·href="ssg-almalinux9-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/> |
131588 | ············</xccdf-1.2:check> | 131588 | ············</xccdf-1.2:check> |
131589 | ··········</xccdf-1.2:Rule> | 131589 | ··········</xccdf-1.2:Rule> |
131590 | ········</xccdf-1.2:Group> | 131590 | ········</xccdf-1.2:Group> |
131591 | ······</xccdf-1.2:Group> | 131591 | ······</xccdf-1.2:Group> |
131592 | ····</xccdf-1.2:Benchmark> | 131592 | ····</xccdf-1.2:Benchmark> |
131593 | ··</ds:component> | 131593 | ··</ds:component> |
131594 | ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-oval.xml"·timestamp="2025-0 | 131594 | ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-oval.xml"·timestamp="2025-03-01T22:08:00"> |
131595 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 131595 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
131596 | ······<oval-def:generator> | 131596 | ······<oval-def:generator> |
131597 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 131597 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
131598 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 131598 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
131599 | ········<oval:schema_version>5.11</oval:schema_version> | 131599 | ········<oval:schema_version>5.11</oval:schema_version> |
131600 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 131600 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
131601 | ······</oval-def:generator> | 131601 | ······</oval-def:generator> |
Offset 154336, 6814 lines modified | Offset 154336, 6658 lines modified | ||
154336 | ············</oval-def:arithmetic> | 154336 | ············</oval-def:arithmetic> |
154337 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 154337 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
154338 | ··········</oval-def:arithmetic> | 154338 | ··········</oval-def:arithmetic> |
154339 | ········</oval-def:local_variable> | 154339 | ········</oval-def:local_variable> |
154340 | ······</oval-def:variables> | 154340 | ······</oval-def:variables> |
154341 | ····</oval-def:oval_definitions> | 154341 | ····</oval-def:oval_definitions> |
154342 | ··</ds:component> | 154342 | ··</ds:component> |
154343 | ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"·timestamp="2025-0 | 154343 | ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
154344 | ····<ocil:ocil> | 154344 | ····<ocil:ocil> |
154345 | ······<ocil:generator> | 154345 | ······<ocil:generator> |
154346 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 154346 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
154347 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 154347 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
154348 | ········<ocil:schema_version>2.0</ocil:schema_version> | 154348 | ········<ocil:schema_version>2.0</ocil:schema_version> |
154349 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 154349 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
154350 | ······</ocil:generator> | 154350 | ······</ocil:generator> |
154351 | ······<ocil:questionnaires> | 154351 | ······<ocil:questionnaires> |
154352 | ········<ocil:questionnaire·id="ocil:ssg- | 154352 | ········<ocil:questionnaire·id="ocil:ssg-mount_option_home_nodev_ocil:questionnaire:1"> |
154353 | ··········<ocil:title>Add·nodev·Option·to·/home</ocil:title> | ||
154353 | ··········<ocil:title>Install·AIDE</ocil:title> | ||
154354 | ··········<ocil:actions> | ||
154355 | ············<ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref> | ||
154356 | ··········</ocil:actions> | ||
154357 | ········</ocil:questionnaire> | ||
154358 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_passwd_ocil:questionnaire:1"> | ||
154359 | ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/passwd</ocil:title> | ||
154360 | ··········<ocil:actions> | 154354 | ··········<ocil:actions> |
154361 | ············<ocil:test_action_ref>ocil:ssg- | 154355 | ············<ocil:test_action_ref>ocil:ssg-mount_option_home_nodev_action:testaction:1</ocil:test_action_ref> |
154362 | ··········</ocil:actions> | 154356 | ··········</ocil:actions> |
154363 | ········</ocil:questionnaire> | 154357 | ········</ocil:questionnaire> |
154364 | ········<ocil:questionnaire·id="ocil:ssg- | 154358 | ········<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_etc_shadow_ocil:questionnaire:1"> |
154365 | ··········<ocil:title>Ensure· | 154359 | ··········<ocil:title>Ensure·There·Are·No·Accounts·With·Blank·or·Null·Passwords</ocil:title> |
154366 | ··········<ocil:actions> | 154360 | ··········<ocil:actions> |
154367 | ············<ocil:test_action_ref>ocil:ssg- | 154361 | ············<ocil:test_action_ref>ocil:ssg-no_empty_passwords_etc_shadow_action:testaction:1</ocil:test_action_ref> |
154368 | ··········</ocil:actions> | 154362 | ··········</ocil:actions> |
154369 | ········</ocil:questionnaire> | 154363 | ········</ocil:questionnaire> |
154370 | ········<ocil:questionnaire·id="ocil:ssg-xwindows_runlevel_target_ocil:questionnaire:1"> | ||
154371 | ········ | 154364 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1"> |
154365 | ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title> | ||
154372 | ··········<ocil:actions> | 154366 | ··········<ocil:actions> |
154373 | ············<ocil:test_action_ref>ocil:ssg- | 154367 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref> |
154374 | ··········</ocil:actions> | 154368 | ··········</ocil:actions> |
154375 | ········</ocil:questionnaire> | 154369 | ········</ocil:questionnaire> |
154376 | ········<ocil:questionnaire·id="ocil:ssg- | 154370 | ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1"> |
154377 | ··········<ocil:title> | 154371 | ··········<ocil:title>Enable·PAM</ocil:title> |
154378 | ··········<ocil:actions> | 154372 | ··········<ocil:actions> |
154379 | ············<ocil:test_action_ref>ocil:ssg- | 154373 | ············<ocil:test_action_ref>ocil:ssg-sshd_enable_pam_action:testaction:1</ocil:test_action_ref> |
154380 | ··········</ocil:actions> | 154374 | ··········</ocil:actions> |
154381 | ········</ocil:questionnaire> | 154375 | ········</ocil:questionnaire> |
154382 | ········<ocil:questionnaire·id="ocil:ssg- | 154376 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shells_ocil:questionnaire:1"> |
154383 | ··········<ocil:title> | 154377 | ··········<ocil:title>Verify·Permissions·on·/etc/shells·File</ocil:title> |
154384 | ··········<ocil:actions> | 154378 | ··········<ocil:actions> |
154385 | ············<ocil:test_action_ref>ocil:ssg- | 154379 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shells_action:testaction:1</ocil:test_action_ref> |
154386 | ··········</ocil:actions> | 154380 | ··········</ocil:actions> |
154387 | ········</ocil:questionnaire> | 154381 | ········</ocil:questionnaire> |
154388 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1"> | ||
154389 | ········ | 154382 | ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1"> |
154383 | ··········<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title> | ||
154390 | ··········<ocil:actions> | 154384 | ··········<ocil:actions> |
154391 | ············<ocil:test_action_ref>ocil:ssg- | 154385 | ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref> |
154392 | ··········</ocil:actions> | 154386 | ··········</ocil:actions> |
154393 | ········</ocil:questionnaire> | 154387 | ········</ocil:questionnaire> |
154394 | ········<ocil:questionnaire·id="ocil:ssg- | 154388 | ········<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1"> |
154395 | ··········<ocil:title> | 154389 | ··········<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title> |
154396 | ··········<ocil:actions> | 154390 | ··········<ocil:actions> |
154397 | ············<ocil:test_action_ref>ocil:ssg- | 154391 | ············<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref> |
154398 | ··········</ocil:actions> | 154392 | ··········</ocil:actions> |
154399 | ········</ocil:questionnaire> | 154393 | ········</ocil:questionnaire> |
154400 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1"> | ||
154401 | ········ | 154394 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_shadow_ocil:questionnaire:1"> |
154395 | ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/shadow</ocil:title> | ||
154402 | ··········<ocil:actions> | 154396 | ··········<ocil:actions> |
154403 | ············<ocil:test_action_ref>ocil:ssg- | 154397 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_shadow_action:testaction:1</ocil:test_action_ref> |
154404 | ··········</ocil:actions> | 154398 | ··········</ocil:actions> |
154405 | ········</ocil:questionnaire> | 154399 | ········</ocil:questionnaire> |
154406 | ········<ocil:questionnaire·id="ocil:ssg- | 154400 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_userhelper_ocil:questionnaire:1"> |
154407 | ··········<ocil:title> | 154401 | ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·userhelper</ocil:title> |
154408 | ··········<ocil:actions> | 154402 | ··········<ocil:actions> |
154409 | ············<ocil:test_action_ref>ocil:ssg- | 154403 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_userhelper_action:testaction:1</ocil:test_action_ref> |
154410 | ··········</ocil:actions> | 154404 | ··········</ocil:actions> |
154411 | ········</ocil:questionnaire> | 154405 | ········</ocil:questionnaire> |
154412 | ········<ocil:questionnaire·id="ocil:ssg- | 154406 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1"> |
154413 | ··········<ocil:title> | 154407 | ··········<ocil:title>Record·Any·Attempts·to·Run·chcon</ocil:title> |
154414 | ··········<ocil:actions> | 154408 | ··········<ocil:actions> |
154415 | ············<ocil:test_action_ref>ocil:ssg- | 154409 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref> |
154416 | ··········</ocil:actions> | 154410 | ··········</ocil:actions> |
154417 | ········</ocil:questionnaire> | 154411 | ········</ocil:questionnaire> |
154418 | ········<ocil:questionnaire·id="ocil:ssg- | 154412 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_daily_ocil:questionnaire:1"> |
Max diff block lines reached; 1058266/1070228 bytes (98.88%) of diff not shown. |
Offset 3, 6805 lines modified | Offset 3, 6649 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg- | 10 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nodev_ocil:questionnaire:1"> |
11 | ······<ocil:title>Add·nodev·Option·to·/home</ocil:title> | ||
11 | ······<ocil:title>Install·AIDE</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_passwd_ocil:questionnaire:1"> | ||
17 | ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/passwd</ocil:title> | ||
18 | ······<ocil:actions> | 12 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nodev_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 14 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg- | 16 | ····<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_etc_shadow_ocil:questionnaire:1"> |
23 | ······<ocil:title>Ensure· | 17 | ······<ocil:title>Ensure·There·Are·No·Accounts·With·Blank·or·Null·Passwords</ocil:title> |
24 | ······<ocil:actions> | 18 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-no_empty_passwords_etc_shadow_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 20 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-xwindows_runlevel_target_ocil:questionnaire:1"> | ||
29 | ···· | 22 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1"> |
23 | ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title> | ||
30 | ······<ocil:actions> | 24 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 26 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg- | 28 | ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1"> |
35 | ······<ocil:title> | 29 | ······<ocil:title>Enable·PAM</ocil:title> |
36 | ······<ocil:actions> | 30 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-sshd_enable_pam_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 32 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shells_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 35 | ······<ocil:title>Verify·Permissions·on·/etc/shells·File</ocil:title> |
42 | ······<ocil:actions> | 36 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shells_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 38 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1"> | ||
47 | ···· | 40 | ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1"> |
41 | ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title> | ||
48 | ······<ocil:actions> | 42 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 44 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 46 | ····<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 47 | ······<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title> |
54 | ······<ocil:actions> | 48 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 50 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1"> | ||
59 | ···· | 52 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_shadow_ocil:questionnaire:1"> |
53 | ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/shadow</ocil:title> | ||
60 | ······<ocil:actions> | 54 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_shadow_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 56 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_userhelper_ocil:questionnaire:1"> |
65 | ······<ocil:title> | 59 | ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·userhelper</ocil:title> |
66 | ······<ocil:actions> | 60 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_userhelper_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 62 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 65 | ······<ocil:title>Record·Any·Attempts·to·Run·chcon</ocil:title> |
72 | ······<ocil:actions> | 66 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 68 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_daily_ocil:questionnaire:1"> |
77 | ······<ocil:title> | 71 | ······<ocil:title>Verify·Permissions·on·cron.daily</ocil:title> |
78 | ······<ocil:actions> | 72 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_daily_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 74 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-enable_authselect_ocil:questionnaire:1"> | ||
83 | ···· | 76 | ····<ocil:questionnaire·id="ocil:ssg-firewalld_loopback_traffic_trusted_ocil:questionnaire:1"> |
77 | ······<ocil:title>Configure·Firewalld·to·Trust·Loopback·Traffic</ocil:title> | ||
84 | ······<ocil:actions> | 78 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg-e | 79 | ········<ocil:test_action_ref>ocil:ssg-firewalld_loopback_traffic_trusted_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 80 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1"> | ||
89 | ···· | 82 | ····<ocil:questionnaire·id="ocil:ssg-service_rsyncd_disabled_ocil:questionnaire:1"> |
83 | ······<ocil:title>Ensure·rsyncd·service·is·disabled</ocil:title> | ||
90 | ······<ocil:actions> | 84 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-service_rsyncd_disabled_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 86 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-package_pam_pwquality_installed_ocil:questionnaire:1"> | ||
95 | ···· | 88 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1"> |
89 | ······<ocil:title>Disable·X11·Forwarding</ocil:title> | ||
96 | ······<ocil:actions> | 90 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 92 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-r | 94 | ····<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1"> |
101 | ······<ocil:title> | 95 | ······<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title> |
102 | ······<ocil:actions> | 96 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg-r | 97 | ········<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 98 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dictcheck_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 101 | ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Prevent·the·Use·of·Dictionary·Words</ocil:title> |
108 | ······<ocil:actions> | 102 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dictcheck_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 104 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-kernel_module_cramfs_disabled_ocil:questionnaire:1"> | ||
113 | ···· | 106 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_usr_share_ocil:questionnaire:1"> |
107 | ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls·in·usr/share</ocil:title> | ||
114 | ······<ocil:actions> | 108 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_usr_share_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 110 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_passwordauth_ocil:questionnaire:1"> | ||
119 | ···· | 112 | ····<ocil:questionnaire·id="ocil:ssg-configure_ssh_crypto_policy_ocil:questionnaire:1"> |
113 | ······<ocil:title>Configure·SSH·to·use·System·Crypto·Policy</ocil:title> | ||
120 | ······<ocil:actions> | 114 | ······<ocil:actions> |
Max diff block lines reached; 1009560/1021639 bytes (98.82%) of diff not shown. |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:23"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:23"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·23</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·23</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml">oval:ssg-installed_OS_is_anolis23:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml">oval:ssg-installed_OS_is_anolis23:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-23"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-23"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·23</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·23</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Anolis·OS·23.·It·is·a·rendering·of | 40 | configuration·settings·for·Anolis·OS·23.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 66305, 15 lines modified | Offset 66305, 15 lines modified | ||
66305 | ··············<xccdf-1.2:check-content-ref·href="ssg-anolis23-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> | 66305 | ··············<xccdf-1.2:check-content-ref·href="ssg-anolis23-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> |
66306 | ············</xccdf-1.2:check> | 66306 | ············</xccdf-1.2:check> |
66307 | ··········</xccdf-1.2:Rule> | 66307 | ··········</xccdf-1.2:Rule> |
66308 | ········</xccdf-1.2:Group> | 66308 | ········</xccdf-1.2:Group> |
66309 | ······</xccdf-1.2:Group> | 66309 | ······</xccdf-1.2:Group> |
66310 | ····</xccdf-1.2:Benchmark> | 66310 | ····</xccdf-1.2:Benchmark> |
66311 | ··</ds:component> | 66311 | ··</ds:component> |
66312 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-oval.xml"·timestamp="2025-0 | 66312 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-oval.xml"·timestamp="2025-03-01T22:08:00"> |
66313 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 66313 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
66314 | ······<oval-def:generator> | 66314 | ······<oval-def:generator> |
66315 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 66315 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
66316 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 66316 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
66317 | ········<oval:schema_version>5.11</oval:schema_version> | 66317 | ········<oval:schema_version>5.11</oval:schema_version> |
66318 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 66318 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
66319 | ······</oval-def:generator> | 66319 | ······</oval-def:generator> |
Offset 90165, 7611 lines modified | Offset 90165, 7701 lines modified | ||
90165 | ············</oval-def:arithmetic> | 90165 | ············</oval-def:arithmetic> |
90166 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 90166 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
90167 | ··········</oval-def:arithmetic> | 90167 | ··········</oval-def:arithmetic> |
90168 | ········</oval-def:local_variable> | 90168 | ········</oval-def:local_variable> |
90169 | ······</oval-def:variables> | 90169 | ······</oval-def:variables> |
90170 | ····</oval-def:oval_definitions> | 90170 | ····</oval-def:oval_definitions> |
90171 | ··</ds:component> | 90171 | ··</ds:component> |
90172 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-ocil.xml"·timestamp="2025-0 | 90172 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
90173 | ····<ocil:ocil> | 90173 | ····<ocil:ocil> |
90174 | ······<ocil:generator> | 90174 | ······<ocil:generator> |
90175 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 90175 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
90176 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 90176 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
90177 | ········<ocil:schema_version>2.0</ocil:schema_version> | 90177 | ········<ocil:schema_version>2.0</ocil:schema_version> |
90178 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 90178 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
90179 | ······</ocil:generator> | 90179 | ······</ocil:generator> |
90180 | ······<ocil:questionnaires> | 90180 | ······<ocil:questionnaires> |
90181 | ········<ocil:questionnaire·id="ocil:ssg- | 90181 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1"> |
90182 | ··········<ocil:title> | 90182 | ··········<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title> |
90183 | ··········<ocil:actions> | 90183 | ··········<ocil:actions> |
90184 | ············<ocil:test_action_ref>ocil:ssg- | 90184 | ············<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref> |
90185 | ··········</ocil:actions> | 90185 | ··········</ocil:actions> |
90186 | ········</ocil:questionnaire> | 90186 | ········</ocil:questionnaire> |
90187 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1"> | ||
90188 | ········ | 90187 | ········<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1"> |
90188 | ··········<ocil:title>Ensure·gpgcheck·Enabled·In·Main·yum·Configuration</ocil:title> | ||
90189 | ··········<ocil:actions> | 90189 | ··········<ocil:actions> |
90190 | ············<ocil:test_action_ref>ocil:ssg- | 90190 | ············<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref> |
90191 | ··········</ocil:actions> | 90191 | ··········</ocil:actions> |
90192 | ········</ocil:questionnaire> | 90192 | ········</ocil:questionnaire> |
90193 | ········<ocil:questionnaire·id="ocil:ssg- | 90193 | ········<ocil:questionnaire·id="ocil:ssg-package_postfix_installed_ocil:questionnaire:1"> |
90194 | ··········<ocil:title> | 90194 | ··········<ocil:title>The·Postfix·package·is·installed</ocil:title> |
90195 | ··········<ocil:actions> | 90195 | ··········<ocil:actions> |
90196 | ············<ocil:test_action_ref>ocil:ssg- | 90196 | ············<ocil:test_action_ref>ocil:ssg-package_postfix_installed_action:testaction:1</ocil:test_action_ref> |
90197 | ··········</ocil:actions> | 90197 | ··········</ocil:actions> |
90198 | ········</ocil:questionnaire> | 90198 | ········</ocil:questionnaire> |
90199 | ········<ocil:questionnaire·id="ocil:ssg- | 90199 | ········<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1"> |
90200 | ··········<ocil:title> | 90200 | ··········<ocil:title>Modify·the·System·Login·Banner</ocil:title> |
90201 | ··········<ocil:actions> | 90201 | ··········<ocil:actions> |
90202 | ············<ocil:test_action_ref>ocil:ssg- | 90202 | ············<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref> |
90203 | ··········</ocil:actions> | 90203 | ··········</ocil:actions> |
90204 | ········</ocil:questionnaire> | 90204 | ········</ocil:questionnaire> |
90205 | ········<ocil:questionnaire·id="ocil:ssg- | 90205 | ········<ocil:questionnaire·id="ocil:ssg-service_rsyncd_disabled_ocil:questionnaire:1"> |
90206 | ··········<ocil:title> | 90206 | ··········<ocil:title>Ensure·rsyncd·service·is·disabled</ocil:title> |
90207 | ··········<ocil:actions> | 90207 | ··········<ocil:actions> |
90208 | ············<ocil:test_action_ref>ocil:ssg- | 90208 | ············<ocil:test_action_ref>ocil:ssg-service_rsyncd_disabled_action:testaction:1</ocil:test_action_ref> |
90209 | ··········</ocil:actions> | 90209 | ··········</ocil:actions> |
90210 | ········</ocil:questionnaire> | 90210 | ········</ocil:questionnaire> |
90211 | ········<ocil:questionnaire·id="ocil:ssg- | 90211 | ········<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1"> |
90212 | ··········<ocil:title> | 90212 | ··········<ocil:title>Enable·systemd-journald·Service</ocil:title> |
90213 | ··········<ocil:actions> | 90213 | ··········<ocil:actions> |
90214 | ············<ocil:test_action_ref>ocil:ssg- | 90214 | ············<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref> |
90215 | ··········</ocil:actions> | 90215 | ··········</ocil:actions> |
90216 | ········</ocil:questionnaire> | 90216 | ········</ocil:questionnaire> |
90217 | ········<ocil:questionnaire·id="ocil:ssg- | 90217 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1"> |
90218 | ··········<ocil:title> | 90218 | ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title> |
90219 | ··········<ocil:actions> | 90219 | ··········<ocil:actions> |
90220 | ············<ocil:test_action_ref>ocil:ssg- | 90220 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref> |
90221 | ··········</ocil:actions> | 90221 | ··········</ocil:actions> |
90222 | ········</ocil:questionnaire> | 90222 | ········</ocil:questionnaire> |
90223 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_security_writable_hooks_ocil:questionnaire:1"> | ||
90224 | ········ | 90223 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1"> |
90224 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title> | ||
90225 | ··········<ocil:actions> | 90225 | ··········<ocil:actions> |
90226 | ············<ocil:test_action_ref>ocil:ssg- | 90226 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref> |
90227 | ··········</ocil:actions> | 90227 | ··········</ocil:actions> |
90228 | ········</ocil:questionnaire> | 90228 | ········</ocil:questionnaire> |
90229 | ········<ocil:questionnaire·id="ocil:ssg- | 90229 | ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1"> |
90230 | ··········<ocil:title> | 90230 | ··········<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title> |
90231 | ··········<ocil:actions> | 90231 | ··········<ocil:actions> |
90232 | ············<ocil:test_action_ref>ocil:ssg- | 90232 | ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref> |
90233 | ··········</ocil:actions> | 90233 | ··········</ocil:actions> |
90234 | ········</ocil:questionnaire> | 90234 | ········</ocil:questionnaire> |
90235 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_sha512_ocil:questionnaire:1"> | ||
90236 | ········ | 90235 | ········<ocil:questionnaire·id="ocil:ssg-file_groupownership_home_directories_ocil:questionnaire:1"> |
90236 | ··········<ocil:title>All·Interactive·User·Home·Directories·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title> | ||
90237 | ··········<ocil:actions> | 90237 | ··········<ocil:actions> |
90238 | ············<ocil:test_action_ref>ocil:ssg- | 90238 | ············<ocil:test_action_ref>ocil:ssg-file_groupownership_home_directories_action:testaction:1</ocil:test_action_ref> |
90239 | ··········</ocil:actions> | 90239 | ··········</ocil:actions> |
90240 | ········</ocil:questionnaire> | 90240 | ········</ocil:questionnaire> |
90241 | ········<ocil:questionnaire·id="ocil:ssg- | 90241 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount2_ocil:questionnaire:1"> |
90242 | ··········<ocil:title> | 90242 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount2</ocil:title> |
90243 | ··········<ocil:actions> | 90243 | ··········<ocil:actions> |
90244 | ············<ocil:test_action_ref>ocil:ssg- | 90244 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount2_action:testaction:1</ocil:test_action_ref> |
90245 | ··········</ocil:actions> | 90245 | ··········</ocil:actions> |
90246 | ········</ocil:questionnaire> | 90246 | ········</ocil:questionnaire> |
90247 | ········<ocil:questionnaire·id="ocil:ssg- | 90247 | ········<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1"> |
90248 | ··········<ocil:title> | 90248 | ··········<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title> |
Max diff block lines reached; 1042952/1055046 bytes (98.85%) of diff not shown. |
Offset 3, 7602 lines modified | Offset 3, 7692 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg- | 10 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1"> |
11 | ······<ocil:title> | 11 | ······<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title> |
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1"> | ||
17 | ···· | 16 | ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1"> |
17 | ······<ocil:title>Ensure·gpgcheck·Enabled·In·Main·yum·Configuration</ocil:title> | ||
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-package_postfix_installed_ocil:questionnaire:1"> |
23 | ······<ocil:title> | 23 | ······<ocil:title>The·Postfix·package·is·installed</ocil:title> |
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-package_postfix_installed_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg- | 28 | ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1"> |
29 | ······<ocil:title> | 29 | ······<ocil:title>Modify·the·System·Login·Banner</ocil:title> |
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-service_rsyncd_disabled_ocil:questionnaire:1"> |
35 | ······<ocil:title> | 35 | ······<ocil:title>Ensure·rsyncd·service·is·disabled</ocil:title> |
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-service_rsyncd_disabled_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 40 | ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 41 | ······<ocil:title>Enable·systemd-journald·Service</ocil:title> |
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_weekly_ocil:questionnaire:1"> | ||
47 | ···· | 46 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1"> |
47 | ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title> | ||
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_writable_hooks_ocil:questionnaire:1"> | ||
53 | ···· | 52 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1"> |
53 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title> | ||
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1"> | ||
59 | ···· | 58 | ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1"> |
59 | ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title> | ||
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_sha512_ocil:questionnaire:1"> | ||
65 | ···· | 64 | ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_home_directories_ocil:questionnaire:1"> |
65 | ······<ocil:title>All·Interactive·User·Home·Directories·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title> | ||
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-file_groupownership_home_directories_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1"> | ||
71 | ···· | 70 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount2_ocil:questionnaire:1"> |
71 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount2</ocil:title> | ||
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount2_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg- | 76 | ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1"> |
77 | ······<ocil:title> | 77 | ······<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title> |
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg- | 82 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 83 | ······<ocil:title>Verify·Permissions·on·crontab</ocil:title> |
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1"> | ||
89 | ···· | 88 | ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_ocil:questionnaire:1"> |
89 | ······<ocil:title>Configure·System·to·Forward·All·Mail·From·Postmaster·to·The·Root·Account</ocil:title> | ||
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg-file_o | 91 | ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_postmaster_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg- | 94 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 95 | ······<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title> |
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_issue_ocil:questionnaire:1"> | ||
101 | ···· | 100 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1"> |
101 | ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title> | ||
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-dir_ | 106 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_delete_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 107 | ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Unloading·-·delete_module</ocil:title> |
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg-dir_ | 109 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_delete_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg- | 112 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 113 | ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title> |
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg- | 118 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1"> |
119 | ······<ocil:title> | 119 | ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title> |
120 | ······<ocil:actions> | 120 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg- | 121 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref> |
Max diff block lines reached; 994547/1007102 bytes (98.75%) of diff not shown. |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:8"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:8"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·8</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·8</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml">oval:ssg-installed_OS_is_anolis8:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml">oval:ssg-installed_OS_is_anolis8:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·8</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·8</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Anolis·OS·8.·It·is·a·rendering·of | 40 | configuration·settings·for·Anolis·OS·8.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 66305, 15 lines modified | Offset 66305, 15 lines modified | ||
66305 | ··············<xccdf-1.2:check-content-ref·href="ssg-anolis8-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> | 66305 | ··············<xccdf-1.2:check-content-ref·href="ssg-anolis8-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> |
66306 | ············</xccdf-1.2:check> | 66306 | ············</xccdf-1.2:check> |
66307 | ··········</xccdf-1.2:Rule> | 66307 | ··········</xccdf-1.2:Rule> |
66308 | ········</xccdf-1.2:Group> | 66308 | ········</xccdf-1.2:Group> |
66309 | ······</xccdf-1.2:Group> | 66309 | ······</xccdf-1.2:Group> |
66310 | ····</xccdf-1.2:Benchmark> | 66310 | ····</xccdf-1.2:Benchmark> |
66311 | ··</ds:component> | 66311 | ··</ds:component> |
66312 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-oval.xml"·timestamp="2025-0 | 66312 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-oval.xml"·timestamp="2025-03-01T22:08:00"> |
66313 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 66313 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
66314 | ······<oval-def:generator> | 66314 | ······<oval-def:generator> |
66315 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 66315 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
66316 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 66316 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
66317 | ········<oval:schema_version>5.11</oval:schema_version> | 66317 | ········<oval:schema_version>5.11</oval:schema_version> |
66318 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 66318 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
66319 | ······</oval-def:generator> | 66319 | ······</oval-def:generator> |
Offset 90165, 6620 lines modified | Offset 90165, 6614 lines modified | ||
90165 | ············</oval-def:arithmetic> | 90165 | ············</oval-def:arithmetic> |
90166 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 90166 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
90167 | ··········</oval-def:arithmetic> | 90167 | ··········</oval-def:arithmetic> |
90168 | ········</oval-def:local_variable> | 90168 | ········</oval-def:local_variable> |
90169 | ······</oval-def:variables> | 90169 | ······</oval-def:variables> |
90170 | ····</oval-def:oval_definitions> | 90170 | ····</oval-def:oval_definitions> |
90171 | ··</ds:component> | 90171 | ··</ds:component> |
90172 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-ocil.xml"·timestamp="2025-0 | 90172 | ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
90173 | ····<ocil:ocil> | 90173 | ····<ocil:ocil> |
90174 | ······<ocil:generator> | 90174 | ······<ocil:generator> |
90175 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 90175 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
90176 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 90176 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
90177 | ········<ocil:schema_version>2.0</ocil:schema_version> | 90177 | ········<ocil:schema_version>2.0</ocil:schema_version> |
90178 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 90178 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
90179 | ······</ocil:generator> | 90179 | ······</ocil:generator> |
90180 | ······<ocil:questionnaires> | 90180 | ······<ocil:questionnaires> |
90181 | ········<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1"> | ||
90182 | ··········<ocil:title>Modify·the·System·Login·Banner</ocil:title> | ||
90183 | ··········<ocil:actions> | ||
90184 | ············<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref> | ||
90185 | ··········</ocil:actions> | ||
90186 | ········</ocil:questionnaire> | ||
90187 | ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1"> | ||
90188 | ··········<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title> | ||
90189 | ··········<ocil:actions> | ||
90190 | ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref> | ||
90191 | ··········</ocil:actions> | ||
90192 | ········</ocil:questionnaire> | ||
90193 | ········<ocil:questionnaire·id="ocil:ssg- | 90181 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1"> |
90194 | ··········<ocil:title> | 90182 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title> |
90195 | ··········<ocil:actions> | 90183 | ··········<ocil:actions> |
90196 | ············<ocil:test_action_ref>ocil:ssg- | 90184 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref> |
90197 | ··········</ocil:actions> | 90185 | ··········</ocil:actions> |
90198 | ········</ocil:questionnaire> | 90186 | ········</ocil:questionnaire> |
90199 | ········<ocil:questionnaire·id="ocil:ssg- | 90187 | ········<ocil:questionnaire·id="ocil:ssg-account_unique_name_ocil:questionnaire:1"> |
90200 | ··········<ocil:title> | 90188 | ··········<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·Names</ocil:title> |
90201 | ··········<ocil:actions> | 90189 | ··········<ocil:actions> |
90202 | ············<ocil:test_action_ref>ocil:ssg- | 90190 | ············<ocil:test_action_ref>ocil:ssg-account_unique_name_action:testaction:1</ocil:test_action_ref> |
90203 | ··········</ocil:actions> | 90191 | ··········</ocil:actions> |
90204 | ········</ocil:questionnaire> | 90192 | ········</ocil:questionnaire> |
90205 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1"> | ||
90206 | ········ | 90193 | ········<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1"> |
90194 | ··········<ocil:title>Set·Password·Minimum·Age</ocil:title> | ||
90207 | ··········<ocil:actions> | 90195 | ··········<ocil:actions> |
90208 | ············<ocil:test_action_ref>ocil:ssg- | 90196 | ············<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref> |
90209 | ··········</ocil:actions> | 90197 | ··········</ocil:actions> |
90210 | ········</ocil:questionnaire> | 90198 | ········</ocil:questionnaire> |
90211 | ········<ocil:questionnaire·id="ocil:ssg- | 90199 | ········<ocil:questionnaire·id="ocil:ssg-chronyd_server_directive_ocil:questionnaire:1"> |
90212 | ··········<ocil:title> | 90200 | ··········<ocil:title>Ensure·Chrony·is·only·configured·with·the·server·directive</ocil:title> |
90213 | ··········<ocil:actions> | 90201 | ··········<ocil:actions> |
90214 | ············<ocil:test_action_ref>ocil:ssg- | 90202 | ············<ocil:test_action_ref>ocil:ssg-chronyd_server_directive_action:testaction:1</ocil:test_action_ref> |
90215 | ··········</ocil:actions> | 90203 | ··········</ocil:actions> |
90216 | ········</ocil:questionnaire> | 90204 | ········</ocil:questionnaire> |
90217 | ········<ocil:questionnaire·id="ocil:ssg-con | 90205 | ········<ocil:questionnaire·id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1"> |
90218 | ··········<ocil:title> | 90206 | ··········<ocil:title>Set·Password·Warning·Age</ocil:title> |
90219 | ··········<ocil:actions> | 90207 | ··········<ocil:actions> |
90220 | ············<ocil:test_action_ref>ocil:ssg-con | 90208 | ············<ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref> |
90221 | ··········</ocil:actions> | 90209 | ··········</ocil:actions> |
90222 | ········</ocil:questionnaire> | 90210 | ········</ocil:questionnaire> |
90223 | ········<ocil:questionnaire·id="ocil:ssg- | 90211 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_ocil:questionnaire:1"> |
90224 | ··········<ocil:title> | 90212 | ··········<ocil:title>Prevent·Routing·External·Traffic·to·Local·Loopback·on·All·IPv4·Interfaces</ocil:title> |
90225 | ··········<ocil:actions> | 90213 | ··········<ocil:actions> |
90226 | ············<ocil:test_action_ref>ocil:ssg- | 90214 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_action:testaction:1</ocil:test_action_ref> |
90227 | ··········</ocil:actions> | 90215 | ··········</ocil:actions> |
90228 | ········</ocil:questionnaire> | 90216 | ········</ocil:questionnaire> |
90229 | ········<ocil:questionnaire·id="ocil:ssg- | 90217 | ········<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1"> |
90230 | ··········<ocil:title> | 90218 | ··········<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title> |
90231 | ··········<ocil:actions> | 90219 | ··········<ocil:actions> |
90232 | ············<ocil:test_action_ref>ocil:ssg- | 90220 | ············<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref> |
90233 | ··········</ocil:actions> | 90221 | ··········</ocil:actions> |
90234 | ········</ocil:questionnaire> | 90222 | ········</ocil:questionnaire> |
90235 | ········<ocil:questionnaire·id="ocil:ssg- | 90223 | ········<ocil:questionnaire·id="ocil:ssg-configure_ssh_crypto_policy_ocil:questionnaire:1"> |
90236 | ··········<ocil:title> | 90224 | ··········<ocil:title>Configure·SSH·to·use·System·Crypto·Policy</ocil:title> |
90237 | ··········<ocil:actions> | 90225 | ··········<ocil:actions> |
90238 | ············<ocil:test_action_ref>ocil:ssg- | 90226 | ············<ocil:test_action_ref>ocil:ssg-configure_ssh_crypto_policy_action:testaction:1</ocil:test_action_ref> |
90239 | ··········</ocil:actions> | 90227 | ··········</ocil:actions> |
90240 | ········</ocil:questionnaire> | 90228 | ········</ocil:questionnaire> |
90241 | ········<ocil:questionnaire·id="ocil:ssg- | 90229 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> |
90242 | ··········<ocil:title> | 90230 | ··········<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title> |
90243 | ··········<ocil:actions> | 90231 | ··········<ocil:actions> |
90244 | ············<ocil:test_action_ref>ocil:ssg- | 90232 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref> |
90245 | ··········</ocil:actions> | 90233 | ··········</ocil:actions> |
90246 | ········</ocil:questionnaire> | 90234 | ········</ocil:questionnaire> |
90247 | ········<ocil:questionnaire·id="ocil:ssg- | 90235 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1"> |
90248 | ··········<ocil:title> | 90236 | ··········<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title> |
90249 | ··········<ocil:actions> | 90237 | ··········<ocil:actions> |
90250 | ············<ocil:test_action_ref>ocil:ssg- | 90238 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref> |
Max diff block lines reached; 1044754/1056514 bytes (98.89%) of diff not shown. |
Offset 3, 6611 lines modified | Offset 3, 6605 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1"> | ||
11 | ······<ocil:title>Modify·the·System·Login·Banner</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1"> | ||
17 | ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title> | ||
18 | ······<ocil:actions> | ||
19 | ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref> | ||
20 | ······</ocil:actions> | ||
21 | ····</ocil:questionnaire> | ||
22 | ····<ocil:questionnaire·id="ocil:ssg- | 10 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1"> |
23 | ······<ocil:title> | 11 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title> |
24 | ······<ocil:actions> | 12 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 14 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg- | 16 | ····<ocil:questionnaire·id="ocil:ssg-account_unique_name_ocil:questionnaire:1"> |
29 | ······<ocil:title> | 17 | ······<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·Names</ocil:title> |
30 | ······<ocil:actions> | 18 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-account_unique_name_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 20 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1"> | ||
35 | ···· | 22 | ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1"> |
23 | ······<ocil:title>Set·Password·Minimum·Age</ocil:title> | ||
36 | ······<ocil:actions> | 24 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 26 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 28 | ····<ocil:questionnaire·id="ocil:ssg-chronyd_server_directive_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 29 | ······<ocil:title>Ensure·Chrony·is·only·configured·with·the·server·directive</ocil:title> |
42 | ······<ocil:actions> | 30 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-chronyd_server_directive_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 32 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1"> | ||
47 | ···· | 34 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1"> |
35 | ······<ocil:title>Set·Password·Warning·Age</ocil:title> | ||
48 | ······<ocil:actions> | 36 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg-con | 37 | ········<ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 38 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 40 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 41 | ······<ocil:title>Prevent·Routing·External·Traffic·to·Local·Loopback·on·All·IPv4·Interfaces</ocil:title> |
54 | ······<ocil:actions> | 42 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 44 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg- | 46 | ····<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 47 | ······<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title> |
60 | ······<ocil:actions> | 48 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 50 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1"> | ||
65 | ···· | 52 | ····<ocil:questionnaire·id="ocil:ssg-configure_ssh_crypto_policy_ocil:questionnaire:1"> |
53 | ······<ocil:title>Configure·SSH·to·use·System·Crypto·Policy</ocil:title> | ||
66 | ······<ocil:actions> | 54 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-configure_ssh_crypto_policy_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 56 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 59 | ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title> |
72 | ······<ocil:actions> | 60 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 62 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-sshd_set_maxstartups_ocil:questionnaire:1"> | ||
77 | ···· | 64 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1"> |
65 | ······<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title> | ||
78 | ······<ocil:actions> | 66 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 68 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1"> | ||
83 | ···· | 70 | ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_audit_configuration_ocil:questionnaire:1"> |
71 | ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Group·root</ocil:title> | ||
84 | ······<ocil:actions> | 72 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-file_groupownership_audit_configuration_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 74 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_c | 76 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1"> |
89 | ······<ocil:title>Verify· | 77 | ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title> |
90 | ······<ocil:actions> | 78 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg-file_owner_c | 79 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 80 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-configure_user_data_backups_ocil:questionnaire:1"> | ||
95 | ···· | 82 | ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1"> |
83 | ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title> | ||
96 | ······<ocil:actions> | 84 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 86 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_ | 88 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1"> |
101 | ······<ocil:title>Verify· | 89 | ······<ocil:title>Verify·Owner·on·cron.monthly</ocil:title> |
102 | ······<ocil:actions> | 90 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg-file_owner_ | 91 | ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 92 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg- | 94 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 95 | ······<ocil:title>Enable·support·for·BUG()</ocil:title> |
108 | ······<ocil:actions> | 96 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 98 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-service_rdisc_disabled_ocil:questionnaire:1"> | 100 | ····<ocil:questionnaire·id="ocil:ssg-service_rdisc_disabled_ocil:questionnaire:1"> |
113 | ······<ocil:title>Disable·Network·Router·Discovery·Daemon·(rdisc)</ocil:title> | 101 | ······<ocil:title>Disable·Network·Router·Discovery·Daemon·(rdisc)</ocil:title> |
114 | ······<ocil:actions> | 102 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg-service_rdisc_disabled_action:testaction:1</ocil:test_action_ref> | 103 | ········<ocil:test_action_ref>ocil:ssg-service_rdisc_disabled_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 104 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ocil:questionnaire:1"> | ||
119 | ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands</ocil:title> | ||
120 | ······<ocil:actions> | ||
121 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_action:testaction:1</ocil:test_action_ref> | ||
122 | ······</ocil:actions> | ||
123 | ····</ocil:questionnaire> | ||
Max diff block lines reached; 997249/1008700 bytes (98.86%) of diff not shown. |
Offset 19, 15 lines modified | Offset 19, 15 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0"> | 32 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0"> |
33 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title> | 33 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title> |
Offset 75, 15 lines modified | Offset 75, 15 lines modified | ||
75 | ······</cpe-dict:cpe-item> | 75 | ······</cpe-dict:cpe-item> |
76 | ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:8"> | 76 | ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:8"> |
77 | ········<cpe-dict:title·xml:lang="en-us">CentOS·8</cpe-dict:title> | 77 | ········<cpe-dict:title·xml:lang="en-us">CentOS·8</cpe-dict:title> |
78 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_centos8:def:1</cpe-dict:check> | 78 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_centos8:def:1</cpe-dict:check> |
79 | ······</cpe-dict:cpe-item> | 79 | ······</cpe-dict:cpe-item> |
80 | ····</cpe-dict:cpe-list> | 80 | ····</cpe-dict:cpe-list> |
81 | ··</ds:component> | 81 | ··</ds:component> |
82 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-0 | 82 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
83 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 83 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
84 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 84 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
85 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title> | 85 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title> |
86 | ······<xccdf-1.2:description> | 86 | ······<xccdf-1.2:description> |
87 | ········This·guide·presents·a·catalog·of·security-relevant | 87 | ········This·guide·presents·a·catalog·of·security-relevant |
88 | configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of | 88 | configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of |
89 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 89 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 312766, 15 lines modified | Offset 312766, 15 lines modified | ||
312766 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/> | 312766 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/> |
312767 | ············</xccdf-1.2:check> | 312767 | ············</xccdf-1.2:check> |
312768 | ··········</xccdf-1.2:Rule> | 312768 | ··········</xccdf-1.2:Rule> |
312769 | ········</xccdf-1.2:Group> | 312769 | ········</xccdf-1.2:Group> |
312770 | ······</xccdf-1.2:Group> | 312770 | ······</xccdf-1.2:Group> |
312771 | ····</xccdf-1.2:Benchmark> | 312771 | ····</xccdf-1.2:Benchmark> |
312772 | ··</ds:component> | 312772 | ··</ds:component> |
312773 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-0 | 312773 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-03-01T22:08:00"> |
312774 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 312774 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
312775 | ······<oval-def:generator> | 312775 | ······<oval-def:generator> |
312776 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 312776 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
312777 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 312777 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
312778 | ········<oval:schema_version>5.11</oval:schema_version> | 312778 | ········<oval:schema_version>5.11</oval:schema_version> |
312779 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 312779 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
312780 | ······</oval-def:generator> | 312780 | ······</oval-def:generator> |
Offset 379152, 18135 lines modified | Offset 379152, 18135 lines modified | ||
379152 | ············</oval-def:arithmetic> | 379152 | ············</oval-def:arithmetic> |
379153 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/> | 379153 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/> |
379154 | ··········</oval-def:arithmetic> | 379154 | ··········</oval-def:arithmetic> |
379155 | ········</oval-def:local_variable> | 379155 | ········</oval-def:local_variable> |
379156 | ······</oval-def:variables> | 379156 | ······</oval-def:variables> |
379157 | ····</oval-def:oval_definitions> | 379157 | ····</oval-def:oval_definitions> |
379158 | ··</ds:component> | 379158 | ··</ds:component> |
379159 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-0 | 379159 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
379160 | ····<ocil:ocil> | 379160 | ····<ocil:ocil> |
379161 | ······<ocil:generator> | 379161 | ······<ocil:generator> |
379162 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 379162 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
379163 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 379163 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
379164 | ········<ocil:schema_version>2.0</ocil:schema_version> | 379164 | ········<ocil:schema_version>2.0</ocil:schema_version> |
379165 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 379165 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
379166 | ······</ocil:generator> | 379166 | ······</ocil:generator> |
379167 | ······<ocil:questionnaires> | 379167 | ······<ocil:questionnaires> |
379168 | ········<ocil:questionnaire·id="ocil:ssg- | 379168 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1"> |
379169 | ··········<ocil:title> | 379169 | ··········<ocil:title>Verify·User·Who·Owns·Backup·passwd·File</ocil:title> |
379170 | ··········<ocil:actions> | 379170 | ··········<ocil:actions> |
379171 | ············<ocil:test_action_ref>ocil:ssg- | 379171 | ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref> |
379172 | ··········</ocil:actions> | 379172 | ··········</ocil:actions> |
379173 | ········</ocil:questionnaire> | 379173 | ········</ocil:questionnaire> |
379174 | ········<ocil:questionnaire·id="ocil:ssg- | 379174 | ········<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1"> |
379175 | ··········<ocil:title> | 379175 | ··········<ocil:title>Uninstall·rsh-server·Package</ocil:title> |
379176 | ··········<ocil:actions> | 379176 | ··········<ocil:actions> |
379177 | ············<ocil:test_action_ref>ocil:ssg- | 379177 | ············<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref> |
379178 | ··········</ocil:actions> | 379178 | ··········</ocil:actions> |
379179 | ········</ocil:questionnaire> | 379179 | ········</ocil:questionnaire> |
379180 | ········<ocil:questionnaire·id="ocil:ssg- | 379180 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_ocil:questionnaire:1"> |
379181 | ··········<ocil:title> | 379181 | ··········<ocil:title>Emulate·Privileged·Access·Never·(PAN)</ocil:title> |
379182 | ··········<ocil:actions> | 379182 | ··········<ocil:actions> |
379183 | ············<ocil:test_action_ref>ocil:ssg- | 379183 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_action:testaction:1</ocil:test_action_ref> |
379184 | ··········</ocil:actions> | 379184 | ··········</ocil:actions> |
379185 | ········</ocil:questionnaire> | 379185 | ········</ocil:questionnaire> |
379186 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 379186 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_login_uids_ocil:questionnaire:1"> |
379187 | ··········<ocil:title> | 379187 | ··········<ocil:title>Configure·immutable·Audit·login·UIDs</ocil:title> |
379188 | ··········<ocil:actions> | 379188 | ··········<ocil:actions> |
379189 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_ | 379189 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_login_uids_action:testaction:1</ocil:test_action_ref> |
379190 | ··········</ocil:actions> | 379190 | ··········</ocil:actions> |
379191 | ········</ocil:questionnaire> | 379191 | ········</ocil:questionnaire> |
379192 | ········<ocil:questionnaire·id="ocil:ssg- | 379192 | ········<ocil:questionnaire·id="ocil:ssg-selinux_all_devicefiles_labeled_ocil:questionnaire:1"> |
379193 | ··········<ocil:title> | 379193 | ··········<ocil:title>Ensure·No·Device·Files·are·Unlabeled·by·SELinux</ocil:title> |
379194 | ··········<ocil:actions> | 379194 | ··········<ocil:actions> |
379195 | ············<ocil:test_action_ref>ocil:ssg- | 379195 | ············<ocil:test_action_ref>ocil:ssg-selinux_all_devicefiles_labeled_action:testaction:1</ocil:test_action_ref> |
379196 | ··········</ocil:actions> | 379196 | ··········</ocil:actions> |
379197 | ········</ocil:questionnaire> | 379197 | ········</ocil:questionnaire> |
379198 | ········<ocil:questionnaire·id="ocil:ssg-a | 379198 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1"> |
379199 | ··········<ocil:title>Ensure· | 379199 | ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title> |
379200 | ··········<ocil:actions> | 379200 | ··········<ocil:actions> |
379201 | ············<ocil:test_action_ref>ocil:ssg-a | 379201 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref> |
379202 | ··········</ocil:actions> | 379202 | ··········</ocil:actions> |
379203 | ········</ocil:questionnaire> | 379203 | ········</ocil:questionnaire> |
379204 | ········<ocil:questionnaire·id="ocil:ssg- | 379204 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"> |
379205 | ··········<ocil:title> | 379205 | ··········<ocil:title>Configure·audit·according·to·OSPP·requirements</ocil:title> |
379206 | ··········<ocil:actions> | 379206 | ··········<ocil:actions> |
379207 | ············<ocil:test_action_ref>ocil:ssg- | 379207 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_for_ospp_action:testaction:1</ocil:test_action_ref> |
379208 | ··········</ocil:actions> | 379208 | ··········</ocil:actions> |
379209 | ········</ocil:questionnaire> | 379209 | ········</ocil:questionnaire> |
379210 | ········<ocil:questionnaire·id="ocil:ssg- | 379210 | ········<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1"> |
379211 | ··········<ocil:title> | 379211 | ··········<ocil:title>The·Chrony·package·is·installed</ocil:title> |
379212 | ··········<ocil:actions> | 379212 | ··········<ocil:actions> |
379213 | ············<ocil:test_action_ref>ocil:ssg- | 379213 | ············<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref> |
379214 | ··········</ocil:actions> | 379214 | ··········</ocil:actions> |
379215 | ········</ocil:questionnaire> | 379215 | ········</ocil:questionnaire> |
379216 | ········<ocil:questionnaire·id="ocil:ssg- | 379216 | ········<ocil:questionnaire·id="ocil:ssg-sebool_cobbler_can_network_connect_ocil:questionnaire:1"> |
379217 | ··········<ocil:title> | 379217 | ··········<ocil:title>Disable·the·cobbler_can_network_connect·SELinux·Boolean</ocil:title> |
379218 | ··········<ocil:actions> | 379218 | ··········<ocil:actions> |
379219 | ············<ocil:test_action_ref>ocil:ssg- | 379219 | ············<ocil:test_action_ref>ocil:ssg-sebool_cobbler_can_network_connect_action:testaction:1</ocil:test_action_ref> |
379220 | ··········</ocil:actions> | 379220 | ··········</ocil:actions> |
379221 | ········</ocil:questionnaire> | 379221 | ········</ocil:questionnaire> |
379222 | ········<ocil:questionnaire·id="ocil:ssg-s | 379222 | ········<ocil:questionnaire·id="ocil:ssg-package_scap-security-guide_installed_ocil:questionnaire:1"> |
379223 | ··········<ocil:title> | 379223 | ··········<ocil:title>Install·scap-security-guide·Package</ocil:title> |
379224 | ··········<ocil:actions> | 379224 | ··········<ocil:actions> |
379225 | ············<ocil:test_action_ref>ocil:ssg-s | 379225 | ············<ocil:test_action_ref>ocil:ssg-package_scap-security-guide_installed_action:testaction:1</ocil:test_action_ref> |
379226 | ··········</ocil:actions> | 379226 | ··········</ocil:actions> |
379227 | ········</ocil:questionnaire> | 379227 | ········</ocil:questionnaire> |
379228 | ········<ocil:questionnaire·id="ocil:ssg- | 379228 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1"> |
379229 | ··········<ocil:title>Verify· | 379229 | ··········<ocil:title>Verify·Owner·on·crontab</ocil:title> |
379230 | ··········<ocil:actions> | 379230 | ··········<ocil:actions> |
Max diff block lines reached; 3568422/3580548 bytes (99.66%) of diff not shown. |
Offset 19, 27 lines modified | Offset 19, 27 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:10"> | 32 | ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:10"> |
33 | ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·10</cpe-dict:title> | 33 | ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·10</cpe-dict:title> |
34 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_centos10:def:1</cpe-dict:check> | 34 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_centos10:def:1</cpe-dict:check> |
35 | ······</cpe-dict:cpe-item> | 35 | ······</cpe-dict:cpe-item> |
36 | ····</cpe-dict:cpe-list> | 36 | ····</cpe-dict:cpe-list> |
37 | ··</ds:component> | 37 | ··</ds:component> |
38 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-0 | 38 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
39 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 39 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
40 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 40 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
41 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title> | 41 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title> |
42 | ······<xccdf-1.2:description> | 42 | ······<xccdf-1.2:description> |
43 | ········This·guide·presents·a·catalog·of·security-relevant | 43 | ········This·guide·presents·a·catalog·of·security-relevant |
44 | configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of | 44 | configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of |
45 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 45 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 366, 23 lines modified | Offset 366, 23 lines modified | ||
366 | ··········</cpe-lang:logical-test> | 366 | ··········</cpe-lang:logical-test> |
367 | ········</cpe-lang:platform> | 367 | ········</cpe-lang:platform> |
368 | ········<cpe-lang:platform·id="package_bash"> | 368 | ········<cpe-lang:platform·id="package_bash"> |
369 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 369 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
370 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> | 370 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> |
371 | ··········</cpe-lang:logical-test> | 371 | ··········</cpe-lang:logical-test> |
372 | ········</cpe-lang:platform> | 372 | ········</cpe-lang:platform> |
373 | ········<cpe-lang:platform·id="os_linux_ | 373 | ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> |
374 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 374 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
375 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ | 375 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> |
376 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> | ||
377 | ··········</cpe-lang:logical-test> | 376 | ··········</cpe-lang:logical-test> |
378 | ········</cpe-lang:platform> | 377 | ········</cpe-lang:platform> |
379 | ········<cpe-lang:platform·id="os_linux_ | 378 | ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0"> |
380 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 379 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
381 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ | 380 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/> |
381 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> | ||
382 | ··········</cpe-lang:logical-test> | 382 | ··········</cpe-lang:logical-test> |
383 | ········</cpe-lang:platform> | 383 | ········</cpe-lang:platform> |
384 | ········<cpe-lang:platform·id="not_s390x_arch"> | 384 | ········<cpe-lang:platform·id="not_s390x_arch"> |
385 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 385 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
386 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> | 386 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> |
387 | ··········</cpe-lang:logical-test> | 387 | ··········</cpe-lang:logical-test> |
388 | ········</cpe-lang:platform> | 388 | ········</cpe-lang:platform> |
Offset 213008, 15 lines modified | Offset 213008, 15 lines modified | ||
213008 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/> | 213008 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/> |
213009 | ············</xccdf-1.2:check> | 213009 | ············</xccdf-1.2:check> |
213010 | ··········</xccdf-1.2:Rule> | 213010 | ··········</xccdf-1.2:Rule> |
213011 | ········</xccdf-1.2:Group> | 213011 | ········</xccdf-1.2:Group> |
213012 | ······</xccdf-1.2:Group> | 213012 | ······</xccdf-1.2:Group> |
213013 | ····</xccdf-1.2:Benchmark> | 213013 | ····</xccdf-1.2:Benchmark> |
213014 | ··</ds:component> | 213014 | ··</ds:component> |
213015 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-0 | 213015 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-03-01T22:08:00"> |
213016 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 213016 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
213017 | ······<oval-def:generator> | 213017 | ······<oval-def:generator> |
213018 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 213018 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
213019 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 213019 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
213020 | ········<oval:schema_version>5.11</oval:schema_version> | 213020 | ········<oval:schema_version>5.11</oval:schema_version> |
213021 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 213021 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
213022 | ······</oval-def:generator> | 213022 | ······</oval-def:generator> |
Offset 261685, 13718 lines modified | Offset 261685, 13907 lines modified | ||
261685 | ············</oval-def:arithmetic> | 261685 | ············</oval-def:arithmetic> |
261686 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 261686 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
261687 | ··········</oval-def:arithmetic> | 261687 | ··········</oval-def:arithmetic> |
261688 | ········</oval-def:local_variable> | 261688 | ········</oval-def:local_variable> |
261689 | ······</oval-def:variables> | 261689 | ······</oval-def:variables> |
261690 | ····</oval-def:oval_definitions> | 261690 | ····</oval-def:oval_definitions> |
261691 | ··</ds:component> | 261691 | ··</ds:component> |
261692 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-0 | 261692 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
261693 | ····<ocil:ocil> | 261693 | ····<ocil:ocil> |
261694 | ······<ocil:generator> | 261694 | ······<ocil:generator> |
261695 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 261695 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
261696 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 261696 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
261697 | ········<ocil:schema_version>2.0</ocil:schema_version> | 261697 | ········<ocil:schema_version>2.0</ocil:schema_version> |
261698 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 261698 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
261699 | ······</ocil:generator> | 261699 | ······</ocil:generator> |
261700 | ······<ocil:questionnaires> | 261700 | ······<ocil:questionnaires> |
261701 | ········<ocil:questionnaire·id="ocil:ssg-accounts_po | 261701 | ········<ocil:questionnaire·id="ocil:ssg-accounts_password_set_max_life_root_ocil:questionnaire:1"> |
261702 | ··········<ocil:title> | 261702 | ··········<ocil:title>Set·Root·Account·Password·Maximum·Age</ocil:title> |
261703 | ··········<ocil:actions> | 261703 | ··········<ocil:actions> |
261704 | ············<ocil:test_action_ref>ocil:ssg-accounts_po | 261704 | ············<ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_root_action:testaction:1</ocil:test_action_ref> |
261705 | ··········</ocil:actions> | 261705 | ··········</ocil:actions> |
261706 | ········</ocil:questionnaire> | 261706 | ········</ocil:questionnaire> |
261707 | ········<ocil:questionnaire·id="ocil:ssg- | 261707 | ········<ocil:questionnaire·id="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1"> |
261708 | ··········<ocil:title> | 261708 | ··········<ocil:title>Configure·BIND·to·use·System·Crypto·Policy</ocil:title> |
261709 | ··········<ocil:actions> | 261709 | ··········<ocil:actions> |
261710 | ············<ocil:test_action_ref>ocil:ssg- | 261710 | ············<ocil:test_action_ref>ocil:ssg-configure_bind_crypto_policy_action:testaction:1</ocil:test_action_ref> |
261711 | ··········</ocil:actions> | 261711 | ··········</ocil:actions> |
261712 | ········</ocil:questionnaire> | 261712 | ········</ocil:questionnaire> |
261713 | ········<ocil:questionnaire·id="ocil:ssg- | 261713 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_user_cfg_ocil:questionnaire:1"> |
261714 | ··········<ocil:title> | 261714 | ··········<ocil:title>Verify·/boot/grub2/user.cfg·Permissions</ocil:title> |
261715 | ··········<ocil:actions> | 261715 | ··········<ocil:actions> |
261716 | ············<ocil:test_action_ref>ocil:ssg- | 261716 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_user_cfg_action:testaction:1</ocil:test_action_ref> |
261717 | ··········</ocil:actions> | 261717 | ··········</ocil:actions> |
261718 | ········</ocil:questionnaire> | 261718 | ········</ocil:questionnaire> |
261719 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_modules_disabled_ocil:questionnaire:1"> | ||
261720 | ········ | 261719 | ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_enforce_root_ocil:questionnaire:1"> |
261720 | ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Enforce·for·root·User</ocil:title> | ||
261721 | ··········<ocil:actions> | 261721 | ··········<ocil:actions> |
261722 | ············<ocil:test_action_ref>ocil:ssg- | 261722 | ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_enforce_root_action:testaction:1</ocil:test_action_ref> |
261723 | ··········</ocil:actions> | 261723 | ··········</ocil:actions> |
261724 | ········</ocil:questionnaire> | 261724 | ········</ocil:questionnaire> |
261725 | ········<ocil:questionnaire·id="ocil:ssg- | 261725 | ········<ocil:questionnaire·id="ocil:ssg-gid_passwd_group_same_ocil:questionnaire:1"> |
261726 | ··········<ocil:title>A | 261726 | ··········<ocil:title>All·GIDs·referenced·in·/etc/passwd·must·be·defined·in·/etc/group</ocil:title> |
261727 | ··········<ocil:actions> | 261727 | ··········<ocil:actions> |
261728 | ············<ocil:test_action_ref>ocil:ssg- | 261728 | ············<ocil:test_action_ref>ocil:ssg-gid_passwd_group_same_action:testaction:1</ocil:test_action_ref> |
261729 | ··········</ocil:actions> | 261729 | ··········</ocil:actions> |
261730 | ········</ocil:questionnaire> | 261730 | ········</ocil:questionnaire> |
261731 | ········<ocil:questionnaire·id="ocil:ssg- | 261731 | ········<ocil:questionnaire·id="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1"> |
261732 | ··········<ocil:title> | 261732 | ··········<ocil:title>Set·SSH·MaxSessions·limit</ocil:title> |
261733 | ··········<ocil:actions> | 261733 | ··········<ocil:actions> |
261734 | ············<ocil:test_action_ref>ocil:ssg- | 261734 | ············<ocil:test_action_ref>ocil:ssg-sshd_set_max_sessions_action:testaction:1</ocil:test_action_ref> |
261735 | ··········</ocil:actions> | 261735 | ··········</ocil:actions> |
261736 | ········</ocil:questionnaire> | 261736 | ········</ocil:questionnaire> |
261737 | ········<ocil:questionnaire·id="ocil:ssg- | 261737 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1"> |
261738 | ··········<ocil:title> | 261738 | ··········<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title> |
261739 | ··········<ocil:actions> | 261739 | ··········<ocil:actions> |
261740 | ············<ocil:test_action_ref>ocil:ssg- | 261740 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref> |
261741 | ··········</ocil:actions> | 261741 | ··········</ocil:actions> |
Max diff block lines reached; 2241378/2253327 bytes (99.47%) of diff not shown. |
Offset 329, 23 lines modified | Offset 329, 23 lines modified | ||
329 | ······</cpe-lang:logical-test> | 329 | ······</cpe-lang:logical-test> |
330 | ····</cpe-lang:platform> | 330 | ····</cpe-lang:platform> |
331 | ····<cpe-lang:platform·id="package_bash"> | 331 | ····<cpe-lang:platform·id="package_bash"> |
332 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 332 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
333 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> | 333 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> |
334 | ······</cpe-lang:logical-test> | 334 | ······</cpe-lang:logical-test> |
335 | ····</cpe-lang:platform> | 335 | ····</cpe-lang:platform> |
336 | ····<cpe-lang:platform·id="os_linux_ | 336 | ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> |
337 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 337 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
338 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ | 338 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> |
339 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> | ||
340 | ······</cpe-lang:logical-test> | 339 | ······</cpe-lang:logical-test> |
341 | ····</cpe-lang:platform> | 340 | ····</cpe-lang:platform> |
342 | ····<cpe-lang:platform·id="os_linux_ | 341 | ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0"> |
343 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 342 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
344 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ | 343 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/> |
344 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> | ||
345 | ······</cpe-lang:logical-test> | 345 | ······</cpe-lang:logical-test> |
346 | ····</cpe-lang:platform> | 346 | ····</cpe-lang:platform> |
347 | ····<cpe-lang:platform·id="not_s390x_arch"> | 347 | ····<cpe-lang:platform·id="not_s390x_arch"> |
348 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 348 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
349 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> | 349 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> |
350 | ······</cpe-lang:logical-test> | 350 | ······</cpe-lang:logical-test> |
351 | ····</cpe-lang:platform> | 351 | ····</cpe-lang:platform> |
Offset 19, 27 lines modified | Offset 19, 27 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:9"> | 32 | ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:9"> |
33 | ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·9</cpe-dict:title> | 33 | ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·9</cpe-dict:title> |
34 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_centos9:def:1</cpe-dict:check> | 34 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_centos9:def:1</cpe-dict:check> |
35 | ······</cpe-dict:cpe-item> | 35 | ······</cpe-dict:cpe-item> |
36 | ····</cpe-dict:cpe-list> | 36 | ····</cpe-dict:cpe-list> |
37 | ··</ds:component> | 37 | ··</ds:component> |
38 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-0 | 38 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
39 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 39 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
40 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 40 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
41 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title> | 41 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title> |
42 | ······<xccdf-1.2:description> | 42 | ······<xccdf-1.2:description> |
43 | ········This·guide·presents·a·catalog·of·security-relevant | 43 | ········This·guide·presents·a·catalog·of·security-relevant |
44 | configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of | 44 | configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of |
45 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 45 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 305658, 15 lines modified | Offset 305658, 15 lines modified | ||
305658 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/> | 305658 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/> |
305659 | ············</xccdf-1.2:check> | 305659 | ············</xccdf-1.2:check> |
305660 | ··········</xccdf-1.2:Rule> | 305660 | ··········</xccdf-1.2:Rule> |
305661 | ········</xccdf-1.2:Group> | 305661 | ········</xccdf-1.2:Group> |
305662 | ······</xccdf-1.2:Group> | 305662 | ······</xccdf-1.2:Group> |
305663 | ····</xccdf-1.2:Benchmark> | 305663 | ····</xccdf-1.2:Benchmark> |
305664 | ··</ds:component> | 305664 | ··</ds:component> |
305665 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-0 | 305665 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-03-01T22:08:00"> |
305666 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 305666 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
305667 | ······<oval-def:generator> | 305667 | ······<oval-def:generator> |
305668 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 305668 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
305669 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 305669 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
305670 | ········<oval:schema_version>5.11</oval:schema_version> | 305670 | ········<oval:schema_version>5.11</oval:schema_version> |
305671 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 305671 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
305672 | ······</oval-def:generator> | 305672 | ······</oval-def:generator> |
Offset 371382, 20441 lines modified | Offset 371382, 20442 lines modified | ||
371382 | ············</oval-def:arithmetic> | 371382 | ············</oval-def:arithmetic> |
371383 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 371383 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
371384 | ··········</oval-def:arithmetic> | 371384 | ··········</oval-def:arithmetic> |
371385 | ········</oval-def:local_variable> | 371385 | ········</oval-def:local_variable> |
371386 | ······</oval-def:variables> | 371386 | ······</oval-def:variables> |
371387 | ····</oval-def:oval_definitions> | 371387 | ····</oval-def:oval_definitions> |
371388 | ··</ds:component> | 371388 | ··</ds:component> |
371389 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-0 | 371389 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
371390 | ····<ocil:ocil> | 371390 | ····<ocil:ocil> |
371391 | ······<ocil:generator> | 371391 | ······<ocil:generator> |
371392 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 371392 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
371393 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 371393 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
371394 | ········<ocil:schema_version>2.0</ocil:schema_version> | 371394 | ········<ocil:schema_version>2.0</ocil:schema_version> |
371395 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 371395 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
371396 | ······</ocil:generator> | 371396 | ······</ocil:generator> |
371397 | ······<ocil:questionnaires> | 371397 | ······<ocil:questionnaires> |
371398 | ········<ocil:questionnaire·id="ocil:ssg-file_ | 371398 | ········<ocil:questionnaire·id="ocil:ssg-file_audit_tools_group_ownership_ocil:questionnaire:1"> |
371399 | ··········<ocil:title> | 371399 | ··········<ocil:title>Audit·Tools·Must·Be·Group-owned·by·Root</ocil:title> |
371400 | ··········<ocil:actions> | 371400 | ··········<ocil:actions> |
371401 | ············<ocil:test_action_ref>ocil:ssg-file_ | 371401 | ············<ocil:test_action_ref>ocil:ssg-file_audit_tools_group_ownership_action:testaction:1</ocil:test_action_ref> |
371402 | ··········</ocil:actions> | 371402 | ··········</ocil:actions> |
371403 | ········</ocil:questionnaire> | 371403 | ········</ocil:questionnaire> |
371404 | ········<ocil:questionnaire·id="ocil:ssg-sebool_ | 371404 | ········<ocil:questionnaire·id="ocil:ssg-sebool_httpd_ssi_exec_ocil:questionnaire:1"> |
371405 | ··········<ocil:title>Disable·the· | 371405 | ··········<ocil:title>Disable·the·httpd_ssi_exec·SELinux·Boolean</ocil:title> |
371406 | ··········<ocil:actions> | 371406 | ··········<ocil:actions> |
371407 | ············<ocil:test_action_ref>ocil:ssg-sebool_ | 371407 | ············<ocil:test_action_ref>ocil:ssg-sebool_httpd_ssi_exec_action:testaction:1</ocil:test_action_ref> |
371408 | ··········</ocil:actions> | 371408 | ··········</ocil:actions> |
371409 | ········</ocil:questionnaire> | 371409 | ········</ocil:questionnaire> |
371410 | ········<ocil:questionnaire·id="ocil:ssg-se | 371410 | ········<ocil:questionnaire·id="ocil:ssg-sebool_exim_read_user_files_ocil:questionnaire:1"> |
371411 | ··········<ocil:title> | 371411 | ··········<ocil:title>Disable·the·exim_read_user_files·SELinux·Boolean</ocil:title> |
371412 | ··········<ocil:actions> | 371412 | ··········<ocil:actions> |
371413 | ············<ocil:test_action_ref>ocil:ssg-se | 371413 | ············<ocil:test_action_ref>ocil:ssg-sebool_exim_read_user_files_action:testaction:1</ocil:test_action_ref> |
371414 | ··········</ocil:actions> | 371414 | ··········</ocil:actions> |
371415 | ········</ocil:questionnaire> | 371415 | ········</ocil:questionnaire> |
371416 | ········<ocil:questionnaire·id="ocil:ssg- | 371416 | ········<ocil:questionnaire·id="ocil:ssg-file_cron_allow_exists_ocil:questionnaire:1"> |
371417 | ··········<ocil:title> | 371417 | ··········<ocil:title>Ensure·that·/etc/cron.allow·exists</ocil:title> |
371418 | ··········<ocil:actions> | 371418 | ··········<ocil:actions> |
371419 | ············<ocil:test_action_ref>ocil:ssg- | 371419 | ············<ocil:test_action_ref>ocil:ssg-file_cron_allow_exists_action:testaction:1</ocil:test_action_ref> |
371420 | ··········</ocil:actions> | 371420 | ··········</ocil:actions> |
371421 | ········</ocil:questionnaire> | 371421 | ········</ocil:questionnaire> |
371422 | ········<ocil:questionnaire·id="ocil:ssg- | 371422 | ········<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1"> |
371423 | ··········<ocil:title>En | 371423 | ··········<ocil:title>Enable·cron·Service</ocil:title> |
371424 | ··········<ocil:actions> | 371424 | ··········<ocil:actions> |
371425 | ············<ocil:test_action_ref>ocil:ssg- | 371425 | ············<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref> |
371426 | ··········</ocil:actions> | 371426 | ··········</ocil:actions> |
371427 | ········</ocil:questionnaire> | 371427 | ········</ocil:questionnaire> |
371428 | ········<ocil:questionnaire·id="ocil:ssg- | 371428 | ········<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1"> |
371429 | ··········<ocil:title>Disable· | 371429 | ··········<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title> |
371430 | ··········<ocil:actions> | 371430 | ··········<ocil:actions> |
371431 | ············<ocil:test_action_ref>ocil:ssg- | 371431 | ············<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref> |
371432 | ··········</ocil:actions> | 371432 | ··········</ocil:actions> |
371433 | ········</ocil:questionnaire> | 371433 | ········</ocil:questionnaire> |
371434 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_syn_cookies_ocil:questionnaire:1"> | ||
371435 | ········ | 371434 | ········<ocil:questionnaire·id="ocil:ssg-audit_modify_failed_ppc64le_ocil:questionnaire:1"> |
371435 | ··········<ocil:title>Configure·auditing·of·unsuccessful·file·modifications·(ppc64le)</ocil:title> | ||
371436 | ··········<ocil:actions> | 371436 | ··········<ocil:actions> |
371437 | ············<ocil:test_action_ref>ocil:ssg- | 371437 | ············<ocil:test_action_ref>ocil:ssg-audit_modify_failed_ppc64le_action:testaction:1</ocil:test_action_ref> |
371438 | ··········</ocil:actions> | 371438 | ··········</ocil:actions> |
371439 | ········</ocil:questionnaire> | 371439 | ········</ocil:questionnaire> |
371440 | ········<ocil:questionnaire·id="ocil:ssg-s | 371440 | ········<ocil:questionnaire·id="ocil:ssg-sebool_httpd_can_network_relay_ocil:questionnaire:1"> |
371441 | ··········<ocil:title> | 371441 | ··········<ocil:title>Disable·the·httpd_can_network_relay·SELinux·Boolean</ocil:title> |
371442 | ··········<ocil:actions> | 371442 | ··········<ocil:actions> |
371443 | ············<ocil:test_action_ref>ocil:ssg-s | 371443 | ············<ocil:test_action_ref>ocil:ssg-sebool_httpd_can_network_relay_action:testaction:1</ocil:test_action_ref> |
371444 | ··········</ocil:actions> | 371444 | ··········</ocil:actions> |
371445 | ········</ocil:questionnaire> | 371445 | ········</ocil:questionnaire> |
371446 | ········<ocil:questionnaire·id="ocil:ssg- | 371446 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_issue_net_ocil:questionnaire:1"> |
371447 | ··········<ocil:title> | 371447 | ··········<ocil:title>Verify·Group·Ownership·of·System·Login·Banner·for·Remote·Connections</ocil:title> |
371448 | ··········<ocil:actions> | 371448 | ··········<ocil:actions> |
371449 | ············<ocil:test_action_ref>ocil:ssg- | 371449 | ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_net_action:testaction:1</ocil:test_action_ref> |
371450 | ··········</ocil:actions> | 371450 | ··········</ocil:actions> |
371451 | ········</ocil:questionnaire> | 371451 | ········</ocil:questionnaire> |
371452 | ········<ocil:questionnaire·id="ocil:ssg- | 371452 | ········<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_binaries_ocil:questionnaire:1"> |
371453 | ··········<ocil:title> | 371453 | ··········<ocil:title>Verify·that·audit·tools·are·owned·by·root</ocil:title> |
371454 | ··········<ocil:actions> | 371454 | ··········<ocil:actions> |
371455 | ············<ocil:test_action_ref>ocil:ssg- | 371455 | ············<ocil:test_action_ref>ocil:ssg-file_ownership_audit_binaries_action:testaction:1</ocil:test_action_ref> |
371456 | ··········</ocil:actions> | 371456 | ··········</ocil:actions> |
371457 | ········</ocil:questionnaire> | 371457 | ········</ocil:questionnaire> |
371458 | ········<ocil:questionnaire·id="ocil:ssg- | 371458 | ········<ocil:questionnaire·id="ocil:ssg-package_geolite2-city_removed_ocil:questionnaire:1"> |
371459 | ··········<ocil:title> | 371459 | ··········<ocil:title>Uninstall·geolite2-city·Package</ocil:title> |
371460 | ··········<ocil:actions> | 371460 | ··········<ocil:actions> |
371461 | ············<ocil:test_action_ref>ocil:ssg- | 371461 | ············<ocil:test_action_ref>ocil:ssg-package_geolite2-city_removed_action:testaction:1</ocil:test_action_ref> |
371462 | ··········</ocil:actions> | 371462 | ··········</ocil:actions> |
371463 | ········</ocil:questionnaire> | 371463 | ········</ocil:questionnaire> |
Max diff block lines reached; 3438251/3450600 bytes (99.64%) of diff not shown. |
Offset 19, 15 lines modified | Offset 19, 15 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:39"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:39"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Fedora·39</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Fedora·39</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:40"> | 32 | ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:40"> |
33 | ········<cpe-dict:title·xml:lang="en-us">Fedora·40</cpe-dict:title> | 33 | ········<cpe-dict:title·xml:lang="en-us">Fedora·40</cpe-dict:title> |
Offset 51, 15 lines modified | Offset 51, 15 lines modified | ||
51 | ······</cpe-dict:cpe-item> | 51 | ······</cpe-dict:cpe-item> |
52 | ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:45"> | 52 | ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:45"> |
53 | ········<cpe-dict:title·xml:lang="en-us">Fedora·45</cpe-dict:title> | 53 | ········<cpe-dict:title·xml:lang="en-us">Fedora·45</cpe-dict:title> |
54 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check> | 54 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check> |
55 | ······</cpe-dict:cpe-item> | 55 | ······</cpe-dict:cpe-item> |
56 | ····</cpe-dict:cpe-list> | 56 | ····</cpe-dict:cpe-list> |
57 | ··</ds:component> | 57 | ··</ds:component> |
58 | ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-xccdf.xml"·timestamp="2025-0 | 58 | ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
59 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FEDORA"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 59 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FEDORA"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
60 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 60 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
61 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Fedora</xccdf-1.2:title> | 61 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Fedora</xccdf-1.2:title> |
62 | ······<xccdf-1.2:description> | 62 | ······<xccdf-1.2:description> |
63 | ········This·guide·presents·a·catalog·of·security-relevant | 63 | ········This·guide·presents·a·catalog·of·security-relevant |
64 | configuration·settings·for·Fedora.·It·is·a·rendering·of | 64 | configuration·settings·for·Fedora.·It·is·a·rendering·of |
65 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 65 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 224264, 15 lines modified | Offset 224264, 15 lines modified | ||
224264 | ··············<xccdf-1.2:check-content-ref·href="ssg-fedora-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/> | 224264 | ··············<xccdf-1.2:check-content-ref·href="ssg-fedora-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/> |
224265 | ············</xccdf-1.2:check> | 224265 | ············</xccdf-1.2:check> |
224266 | ··········</xccdf-1.2:Rule> | 224266 | ··········</xccdf-1.2:Rule> |
224267 | ········</xccdf-1.2:Group> | 224267 | ········</xccdf-1.2:Group> |
224268 | ······</xccdf-1.2:Group> | 224268 | ······</xccdf-1.2:Group> |
224269 | ····</xccdf-1.2:Benchmark> | 224269 | ····</xccdf-1.2:Benchmark> |
224270 | ··</ds:component> | 224270 | ··</ds:component> |
224271 | ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-oval.xml"·timestamp="2025-0 | 224271 | ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-oval.xml"·timestamp="2025-03-01T22:08:00"> |
224272 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 224272 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
224273 | ······<oval-def:generator> | 224273 | ······<oval-def:generator> |
224274 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 224274 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
224275 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 224275 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
224276 | ········<oval:schema_version>5.11</oval:schema_version> | 224276 | ········<oval:schema_version>5.11</oval:schema_version> |
224277 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 224277 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
224278 | ······</oval-def:generator> | 224278 | ······</oval-def:generator> |
Offset 273035, 11149 lines modified | Offset 273035, 11149 lines modified | ||
273035 | ············</oval-def:arithmetic> | 273035 | ············</oval-def:arithmetic> |
273036 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/> | 273036 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/> |
273037 | ··········</oval-def:arithmetic> | 273037 | ··········</oval-def:arithmetic> |
273038 | ········</oval-def:local_variable> | 273038 | ········</oval-def:local_variable> |
273039 | ······</oval-def:variables> | 273039 | ······</oval-def:variables> |
273040 | ····</oval-def:oval_definitions> | 273040 | ····</oval-def:oval_definitions> |
273041 | ··</ds:component> | 273041 | ··</ds:component> |
273042 | ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-ocil.xml"·timestamp="2025-0 | 273042 | ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
273043 | ····<ocil:ocil> | 273043 | ····<ocil:ocil> |
273044 | ······<ocil:generator> | 273044 | ······<ocil:generator> |
273045 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 273045 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
273046 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 273046 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
273047 | ········<ocil:schema_version>2.0</ocil:schema_version> | 273047 | ········<ocil:schema_version>2.0</ocil:schema_version> |
273048 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 273048 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
273049 | ······</ocil:generator> | 273049 | ······</ocil:generator> |
273050 | ······<ocil:questionnaires> | 273050 | ······<ocil:questionnaires> |
273051 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_ocil:questionnaire:1"> | ||
273052 | ········ | 273051 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1"> |
273052 | ··········<ocil:title>Verify·Group·Who·Owns·cron.hourly</ocil:title> | ||
273053 | ··········<ocil:actions> | 273053 | ··········<ocil:actions> |
273054 | ············<ocil:test_action_ref>ocil:ssg- | 273054 | ············<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref> |
273055 | ··········</ocil:actions> | 273055 | ··········</ocil:actions> |
273056 | ········</ocil:questionnaire> | 273056 | ········</ocil:questionnaire> |
273057 | ········<ocil:questionnaire·id="ocil:ssg- | 273057 | ········<ocil:questionnaire·id="ocil:ssg-package_rsyslog-gnutls_installed_ocil:questionnaire:1"> |
273058 | ··········<ocil:title> | 273058 | ··········<ocil:title>Ensure·rsyslog-gnutls·is·installed</ocil:title> |
273059 | ··········<ocil:actions> | 273059 | ··········<ocil:actions> |
273060 | ············<ocil:test_action_ref>ocil:ssg- | 273060 | ············<ocil:test_action_ref>ocil:ssg-package_rsyslog-gnutls_installed_action:testaction:1</ocil:test_action_ref> |
273061 | ··········</ocil:actions> | 273061 | ··········</ocil:actions> |
273062 | ········</ocil:questionnaire> | 273062 | ········</ocil:questionnaire> |
273063 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_ocil:questionnaire:1"> | ||
273064 | ········ | 273063 | ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_wifi_notification_ocil:questionnaire:1"> |
273064 | ··········<ocil:title>Disable·WIFI·Network·Notification·in·GNOME3</ocil:title> | ||
273065 | ··········<ocil:actions> | 273065 | ··········<ocil:actions> |
273066 | ············<ocil:test_action_ref>ocil:ssg- | 273066 | ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_wifi_notification_action:testaction:1</ocil:test_action_ref> |
273067 | ··········</ocil:actions> | 273067 | ··········</ocil:actions> |
273068 | ········</ocil:questionnaire> | 273068 | ········</ocil:questionnaire> |
273069 | ········<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1"> | ||
273070 | ········ | 273069 | ········<ocil:questionnaire·id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1"> |
273070 | ··········<ocil:title>Deactivate·Wireless·Network·Interfaces</ocil:title> | ||
273071 | ··········<ocil:actions> | 273071 | ··········<ocil:actions> |
273072 | ············<ocil:test_action_ref>ocil:ssg- | 273072 | ············<ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref> |
273073 | ··········</ocil:actions> | 273073 | ··········</ocil:actions> |
273074 | ········</ocil:questionnaire> | 273074 | ········</ocil:questionnaire> |
273075 | ········<ocil:questionnaire·id="ocil:ssg- | 273075 | ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_automount_ocil:questionnaire:1"> |
273076 | ··········<ocil:title> | 273076 | ··········<ocil:title>Disable·GNOME3·Automounting</ocil:title> |
273077 | ··········<ocil:actions> | 273077 | ··········<ocil:actions> |
273078 | ············<ocil:test_action_ref>ocil:ssg- | 273078 | ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_automount_action:testaction:1</ocil:test_action_ref> |
273079 | ··········</ocil:actions> | 273079 | ··········</ocil:actions> |
273080 | ········</ocil:questionnaire> | 273080 | ········</ocil:questionnaire> |
273081 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_ocil:questionnaire:1"> | ||
273082 | ········ | 273081 | ········<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1"> |
273082 | ··········<ocil:title>Enable·cron·Service</ocil:title> | ||
273083 | ··········<ocil:actions> | 273083 | ··········<ocil:actions> |
273084 | ············<ocil:test_action_ref>ocil:ssg- | 273084 | ············<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref> |
273085 | ··········</ocil:actions> | 273085 | ··········</ocil:actions> |
273086 | ········</ocil:questionnaire> | 273086 | ········</ocil:questionnaire> |
273087 | ········<ocil:questionnaire·id="ocil:ssg- | 273087 | ········<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1"> |
273088 | ··········<ocil:title> | 273088 | ··········<ocil:title>Remove·NIS·Client</ocil:title> |
273089 | ··········<ocil:actions> | 273089 | ··········<ocil:actions> |
273090 | ············<ocil:test_action_ref>ocil:ssg- | 273090 | ············<ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref> |
273091 | ··········</ocil:actions> | 273091 | ··········</ocil:actions> |
273092 | ········</ocil:questionnaire> | 273092 | ········</ocil:questionnaire> |
273093 | ········<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_access_monitoring_ocil:questionnaire:1"> | ||
273094 | ········ | 273093 | ········<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_logindefs_ocil:questionnaire:1"> |
273094 | ··········<ocil:title>Set·Password·Hashing·Algorithm·in·/etc/login.defs</ocil:title> | ||
273095 | ··········<ocil:actions> | 273095 | ··········<ocil:actions> |
273096 | ············<ocil:test_action_ref>ocil:ssg- | 273096 | ············<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_logindefs_action:testaction:1</ocil:test_action_ref> |
273097 | ··········</ocil:actions> | 273097 | ··········</ocil:actions> |
273098 | ········</ocil:questionnaire> | 273098 | ········</ocil:questionnaire> |
273099 | ········<ocil:questionnaire·id="ocil:ssg- | 273099 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_etc_group_open_by_handle_at_ocil:questionnaire:1"> |
273100 | ··········<ocil:title> | 273100 | ··········<ocil:title>Record·Events·that·Modify·User/Group·Information·via·open_by_handle_at·syscall·-·/etc/group</ocil:title> |
273101 | ··········<ocil:actions> | 273101 | ··········<ocil:actions> |
273102 | ············<ocil:test_action_ref>ocil:ssg- | 273102 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_etc_group_open_by_handle_at_action:testaction:1</ocil:test_action_ref> |
273103 | ··········</ocil:actions> | 273103 | ··········</ocil:actions> |
273104 | ········</ocil:questionnaire> | 273104 | ········</ocil:questionnaire> |
273105 | ········<ocil:questionnaire·id="ocil:ssg- | 273105 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1"> |
273106 | ··········<ocil:title> | 273106 | ··········<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title> |
273107 | ··········<ocil:actions> | 273107 | ··········<ocil:actions> |
273108 | ············<ocil:test_action_ref>ocil:ssg- | 273108 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref> |
Max diff block lines reached; 2139442/2151228 bytes (99.45%) of diff not shown. |
Offset 3, 11140 lines modified | Offset 3, 11140 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_ocil:questionnaire:1"> | ||
11 | ···· | 10 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1"> |
11 | ······<ocil:title>Verify·Group·Who·Owns·cron.hourly</ocil:title> | ||
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1"> | ||
17 | ···· | 16 | ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog-gnutls_installed_ocil:questionnaire:1"> |
17 | ······<ocil:title>Ensure·rsyslog-gnutls·is·installed</ocil:title> | ||
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-package_rsyslog-gnutls_installed_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_ocil:questionnaire:1"> | ||
23 | ···· | 22 | ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_wifi_notification_ocil:questionnaire:1"> |
23 | ······<ocil:title>Disable·WIFI·Network·Notification·in·GNOME3</ocil:title> | ||
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_wifi_notification_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1"> | ||
29 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1"> |
29 | ······<ocil:title>Deactivate·Wireless·Network·Interfaces</ocil:title> | ||
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1"> | ||
35 | ···· | 34 | ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_automount_ocil:questionnaire:1"> |
35 | ······<ocil:title>Disable·GNOME3·Automounting</ocil:title> | ||
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_automount_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_ocil:questionnaire:1"> | ||
41 | ···· | 40 | ····<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1"> |
41 | ······<ocil:title>Enable·cron·Service</ocil:title> | ||
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg- | 46 | ····<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1"> |
47 | ······<ocil:title> | 47 | ······<ocil:title>Remove·NIS·Client</ocil:title> |
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_access_monitoring_ocil:questionnaire:1"> | ||
53 | ···· | 52 | ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_logindefs_ocil:questionnaire:1"> |
53 | ······<ocil:title>Set·Password·Hashing·Algorithm·in·/etc/login.defs</ocil:title> | ||
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_logindefs_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_crypto_fips_enabled_ocil:questionnaire:1"> | ||
59 | ···· | 58 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_etc_group_open_by_handle_at_ocil:questionnaire:1"> |
59 | ······<ocil:title>Record·Events·that·Modify·User/Group·Information·via·open_by_handle_at·syscall·-·/etc/group</ocil:title> | ||
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_etc_group_open_by_handle_at_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1"> |
65 | ······<ocil:title> | 65 | ······<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title> |
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1"> | ||
71 | ···· | 70 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_ftruncate_ocil:questionnaire:1"> |
71 | ······<ocil:title>Record·Successful·Access·Attempts·to·Files·-·ftruncate</ocil:title> | ||
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-accounts_authorized_local_users_ocil:questionnaire:1"> | ||
77 | ···· | 76 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_audit_auditd_ocil:questionnaire:1"> |
77 | ······<ocil:title>Verify·Permissions·on·/etc/audit/auditd.conf</ocil:title> | ||
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_audit_auditd_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-service_chronyd_or_ntpd_enabled_ocil:questionnaire:1"> | ||
83 | ····· | 82 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_trunc_write_ocil:questionnaire:1"> |
83 | ······<ocil:title>Record·Unsuccessful·Modification·Attempts·to·Files·-·open·O_TRUNC_WRITE</ocil:title> | ||
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg-se | 85 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_trunc_write_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_ocil:questionnaire:1"> | ||
89 | ···· | 88 | ····<ocil:questionnaire·id="ocil:ssg-banner_etc_motd_ocil:questionnaire:1"> |
89 | ······<ocil:title>Modify·the·System·Message·of·the·Day·Banner</ocil:title> | ||
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-banner_etc_motd_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy_ocil:questionnaire:1"> | ||
95 | ···· | 94 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1"> |
95 | ······<ocil:title>Enable·automatic·signing·of·all·modules</ocil:title> | ||
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_all_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ | 100 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_su_ocil:questionnaire:1"> |
101 | ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-· | 101 | ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·su</ocil:title> |
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_ | 103 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_su_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg- | 106 | ····<ocil:questionnaire·id="ocil:ssg-sshd_x11_use_localhost_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 107 | ······<ocil:title>Prevent·remote·hosts·from·connecting·to·the·proxy·display</ocil:title> |
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-sshd_x11_use_localhost_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_rmmod_ocil:questionnaire:1"> | ||
113 | ···· | 112 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_ocil:questionnaire:1"> |
113 | ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</ocil:title> | ||
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref> |
Max diff block lines reached; 2046547/2059039 bytes (99.39%) of diff not shown. |
Offset 19, 15 lines modified | Offset 19, 15 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP1:ga:server"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP1:ga:server"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP1</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP1</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP2:ga:server"> | 32 | ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP2:ga:server"> |
33 | ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP2</cpe-dict:title> | 33 | ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP2</cpe-dict:title> |
Offset 35, 15 lines modified | Offset 35, 15 lines modified | ||
35 | ······</cpe-dict:cpe-item> | 35 | ······</cpe-dict:cpe-item> |
36 | ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP3:ga:server"> | 36 | ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP3:ga:server"> |
37 | ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP3</cpe-dict:title> | 37 | ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP3</cpe-dict:title> |
38 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check> | 38 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check> |
39 | ······</cpe-dict:cpe-item> | 39 | ······</cpe-dict:cpe-item> |
40 | ····</cpe-dict:cpe-list> | 40 | ····</cpe-dict:cpe-list> |
41 | ··</ds:component> | 41 | ··</ds:component> |
42 | ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-xccdf.xml"·timestamp="2025-0 | 42 | ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
43 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_KYLINSERVER10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 43 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_KYLINSERVER10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
44 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 44 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
45 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Kylin·Server·10</xccdf-1.2:title> | 45 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Kylin·Server·10</xccdf-1.2:title> |
46 | ······<xccdf-1.2:description> | 46 | ······<xccdf-1.2:description> |
47 | ········This·guide·presents·a·catalog·of·security-relevant | 47 | ········This·guide·presents·a·catalog·of·security-relevant |
48 | configuration·settings·for·Kylin·Server·10.·It·is·a·rendering·of | 48 | configuration·settings·for·Kylin·Server·10.·It·is·a·rendering·of |
49 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 49 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 20889, 15 lines modified | Offset 20889, 15 lines modified | ||
20889 | ··············<xccdf-1.2:check-content-ref·href="ssg-kylinserver10-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1"/> | 20889 | ··············<xccdf-1.2:check-content-ref·href="ssg-kylinserver10-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1"/> |
20890 | ············</xccdf-1.2:check> | 20890 | ············</xccdf-1.2:check> |
20891 | ··········</xccdf-1.2:Rule> | 20891 | ··········</xccdf-1.2:Rule> |
20892 | ········</xccdf-1.2:Group> | 20892 | ········</xccdf-1.2:Group> |
20893 | ······</xccdf-1.2:Group> | 20893 | ······</xccdf-1.2:Group> |
20894 | ····</xccdf-1.2:Benchmark> | 20894 | ····</xccdf-1.2:Benchmark> |
20895 | ··</ds:component> | 20895 | ··</ds:component> |
20896 | ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"·timestamp="2025-0 | 20896 | ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"·timestamp="2025-03-01T22:08:00"> |
20897 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 20897 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
20898 | ······<oval-def:generator> | 20898 | ······<oval-def:generator> |
20899 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 20899 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
20900 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 20900 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
20901 | ········<oval:schema_version>5.11</oval:schema_version> | 20901 | ········<oval:schema_version>5.11</oval:schema_version> |
20902 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 20902 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
20903 | ······</oval-def:generator> | 20903 | ······</oval-def:generator> |
Offset 26495, 1671 lines modified | Offset 26495, 1654 lines modified | ||
26495 | ············</oval-def:arithmetic> | 26495 | ············</oval-def:arithmetic> |
26496 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 26496 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
26497 | ··········</oval-def:arithmetic> | 26497 | ··········</oval-def:arithmetic> |
26498 | ········</oval-def:local_variable> | 26498 | ········</oval-def:local_variable> |
26499 | ······</oval-def:variables> | 26499 | ······</oval-def:variables> |
26500 | ····</oval-def:oval_definitions> | 26500 | ····</oval-def:oval_definitions> |
26501 | ··</ds:component> | 26501 | ··</ds:component> |
26502 | ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"·timestamp="2025-0 | 26502 | ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
26503 | ····<ocil:ocil> | 26503 | ····<ocil:ocil> |
26504 | ······<ocil:generator> | 26504 | ······<ocil:generator> |
26505 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 26505 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
26506 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 26506 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
26507 | ········<ocil:schema_version>2.0</ocil:schema_version> | 26507 | ········<ocil:schema_version>2.0</ocil:schema_version> |
26508 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 26508 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
26509 | ······</ocil:generator> | 26509 | ······</ocil:generator> |
26510 | ······<ocil:questionnaires> | 26510 | ······<ocil:questionnaires> |
26511 | ········<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1"> | ||
26512 | ··········<ocil:title>Set·Lockout·Time·for·Failed·Password·Attempts</ocil:title> | ||
26511 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1"> | ||
26512 | ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title> | ||
26513 | ··········<ocil:actions> | ||
26514 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref> | ||
26515 | ··········</ocil:actions> | ||
26516 | ········</ocil:questionnaire> | ||
26517 | ········<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1"> | ||
26518 | ··········<ocil:title>Limit·Users'·SSH·Access</ocil:title> | ||
26519 | ··········<ocil:actions> | ||
26520 | ············<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref> | ||
26521 | ··········</ocil:actions> | ||
26522 | ········</ocil:questionnaire> | ||
26523 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1"> | ||
26524 | ··········<ocil:title>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</ocil:title> | ||
26525 | ··········<ocil:actions> | ||
26526 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1</ocil:test_action_ref> | ||
26527 | ··········</ocil:actions> | ||
26528 | ········</ocil:questionnaire> | ||
26529 | ········<ocil:questionnaire·id="ocil:ssg-package_telnet-server_removed_ocil:questionnaire:1"> | ||
26530 | ··········<ocil:title>Uninstall·telnet-server·Package</ocil:title> | ||
26531 | ··········<ocil:actions> | 26513 | ··········<ocil:actions> |
26532 | ············<ocil:test_action_ref>ocil:ssg- | 26514 | ············<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_unlock_time_action:testaction:1</ocil:test_action_ref> |
26533 | ··········</ocil:actions> | 26515 | ··········</ocil:actions> |
26534 | ········</ocil:questionnaire> | 26516 | ········</ocil:questionnaire> |
26535 | ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ | 26517 | ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_lcredit_ocil:questionnaire:1"> |
26536 | ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Le | 26518 | ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Lowercase·Characters</ocil:title> |
26537 | ··········<ocil:actions> | 26519 | ··········<ocil:actions> |
26538 | ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ | 26520 | ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_lcredit_action:testaction:1</ocil:test_action_ref> |
26539 | ··········</ocil:actions> | 26521 | ··········</ocil:actions> |
26540 | ········</ocil:questionnaire> | 26522 | ········</ocil:questionnaire> |
26541 | ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ | 26523 | ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ocredit_ocil:questionnaire:1"> |
26542 | ··········<ocil:title> | 26524 | ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Special·Characters</ocil:title> |
26543 | ··········<ocil:actions> | 26525 | ··········<ocil:actions> |
26544 | ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ | 26526 | ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ocredit_action:testaction:1</ocil:test_action_ref> |
26545 | ··········</ocil:actions> | 26527 | ··········</ocil:actions> |
26546 | ········</ocil:questionnaire> | 26528 | ········</ocil:questionnaire> |
26547 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"> | ||
26548 | ········ | 26529 | ········<ocil:questionnaire·id="ocil:ssg-require_emergency_target_auth_ocil:questionnaire:1"> |
26530 | ··········<ocil:title>Require·Authentication·for·Emergency·Systemd·Target</ocil:title> | ||
26549 | ··········<ocil:actions> | 26531 | ··········<ocil:actions> |
26550 | ············<ocil:test_action_ref>ocil:ssg- | 26532 | ············<ocil:test_action_ref>ocil:ssg-require_emergency_target_auth_action:testaction:1</ocil:test_action_ref> |
26551 | ··········</ocil:actions> | 26533 | ··········</ocil:actions> |
26552 | ········</ocil:questionnaire> | 26534 | ········</ocil:questionnaire> |
26553 | ········<ocil:questionnaire·id="ocil:ssg- | 26535 | ········<ocil:questionnaire·id="ocil:ssg-grub2_password_ocil:questionnaire:1"> |
26554 | ··········<ocil:title> | 26536 | ··········<ocil:title>Set·Boot·Loader·Password·in·grub2</ocil:title> |
26555 | ··········<ocil:actions> | 26537 | ··········<ocil:actions> |
26556 | ············<ocil:test_action_ref>ocil:ssg- | 26538 | ············<ocil:test_action_ref>ocil:ssg-grub2_password_action:testaction:1</ocil:test_action_ref> |
26557 | ··········</ocil:actions> | 26539 | ··········</ocil:actions> |
26558 | ········</ocil:questionnaire> | 26540 | ········</ocil:questionnaire> |
26559 | ········<ocil:questionnaire·id="ocil:ssg-di | 26541 | ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1"> |
26560 | ··········<ocil:title> | 26542 | ··········<ocil:title>Configure·auditd·space_left·on·Low·Disk·Space</ocil:title> |
26561 | ··········<ocil:actions> | 26543 | ··········<ocil:actions> |
26562 | ············<ocil:test_action_ref>ocil:ssg-di | 26544 | ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action:testaction:1</ocil:test_action_ref> |
26563 | ··········</ocil:actions> | 26545 | ··········</ocil:actions> |
26564 | ········</ocil:questionnaire> | 26546 | ········</ocil:questionnaire> |
26565 | ········<ocil:questionnaire·id="ocil:ssg-s | 26547 | ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1"> |
26566 | ··········<ocil:title> | 26548 | ··········<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title> |
26567 | ··········<ocil:actions> | 26549 | ··········<ocil:actions> |
26568 | ············<ocil:test_action_ref>ocil:ssg-s | 26550 | ············<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref> |
26569 | ··········</ocil:actions> | 26551 | ··········</ocil:actions> |
26570 | ········</ocil:questionnaire> | 26552 | ········</ocil:questionnaire> |
Max diff block lines reached; 237459/248793 bytes (95.44%) of diff not shown. |
Offset 3, 1662 lines modified | Offset 3, 1645 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1"> | ||
11 | ······<ocil:title>Set·Lockout·Time·for·Failed·Password·Attempts</ocil:title> | ||
10 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1"> | ||
11 | ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1"> | ||
17 | ······<ocil:title>Limit·Users'·SSH·Access</ocil:title> | ||
18 | ······<ocil:actions> | ||
19 | ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref> | ||
20 | ······</ocil:actions> | ||
21 | ····</ocil:questionnaire> | ||
22 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1"> | ||
23 | ······<ocil:title>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</ocil:title> | ||
24 | ······<ocil:actions> | ||
25 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1</ocil:test_action_ref> | ||
26 | ······</ocil:actions> | ||
27 | ····</ocil:questionnaire> | ||
28 | ····<ocil:questionnaire·id="ocil:ssg-package_telnet-server_removed_ocil:questionnaire:1"> | ||
29 | ······<ocil:title>Uninstall·telnet-server·Package</ocil:title> | ||
30 | ······<ocil:actions> | 12 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_unlock_time_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 14 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ | 16 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_lcredit_ocil:questionnaire:1"> |
35 | ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Le | 17 | ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Lowercase·Characters</ocil:title> |
36 | ······<ocil:actions> | 18 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ | 19 | ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_lcredit_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 20 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ | 22 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ocredit_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 23 | ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Special·Characters</ocil:title> |
42 | ······<ocil:actions> | 24 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ | 25 | ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ocredit_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 26 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"> | ||
47 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-require_emergency_target_auth_ocil:questionnaire:1"> |
29 | ······<ocil:title>Require·Authentication·for·Emergency·Systemd·Target</ocil:title> | ||
48 | ······<ocil:actions> | 30 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-require_emergency_target_auth_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 32 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-grub2_password_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 35 | ······<ocil:title>Set·Boot·Loader·Password·in·grub2</ocil:title> |
54 | ······<ocil:actions> | 36 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-grub2_password_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 38 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-di | 40 | ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 41 | ······<ocil:title>Configure·auditd·space_left·on·Low·Disk·Space</ocil:title> |
60 | ······<ocil:actions> | 42 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg-di | 43 | ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 44 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-s | 46 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1"> |
65 | ······<ocil:title> | 47 | ······<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title> |
66 | ······<ocil:actions> | 48 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg-s | 49 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 50 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 52 | ····<ocil:questionnaire·id="ocil:ssg-sshd_print_last_log_ocil:questionnaire:1"> |
71 | ······<ocil:title>En | 53 | ······<ocil:title>Enable·SSH·Print·Last·Log</ocil:title> |
72 | ······<ocil:actions> | 54 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-sshd_print_last_log_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 56 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-require_singleuser_auth_ocil:questionnaire:1"> | 58 | ····<ocil:questionnaire·id="ocil:ssg-require_singleuser_auth_ocil:questionnaire:1"> |
77 | ······<ocil:title>Require·Authentication·for·Single·User·Mode</ocil:title> | 59 | ······<ocil:title>Require·Authentication·for·Single·User·Mode</ocil:title> |
78 | ······<ocil:actions> | 60 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg-require_singleuser_auth_action:testaction:1</ocil:test_action_ref> | 61 | ········<ocil:test_action_ref>ocil:ssg-require_singleuser_auth_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 62 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-sshd_ | 64 | ····<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_ciphers_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 65 | ······<ocil:title>Use·Only·Strong·Ciphers</ocil:title> |
84 | ······<ocil:actions> | 66 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg-sshd_ | 67 | ········<ocil:test_action_ref>ocil:ssg-sshd_use_strong_ciphers_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 68 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-service_ | 70 | ····<ocil:questionnaire·id="ocil:ssg-service_sshd_enabled_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 71 | ······<ocil:title>Enable·the·OpenSSH·Service</ocil:title> |
90 | ······<ocil:actions> | 72 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg-service_ | 73 | ········<ocil:test_action_ref>ocil:ssg-service_sshd_enabled_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 74 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg- | 76 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 77 | ······<ocil:title>Verify·User·Who·Owns·group·File</ocil:title> |
96 | ······<ocil:actions> | 78 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 80 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ocredit_ocil:questionnaire:1"> | ||
101 | ···· | 82 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"> |
83 | ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title> | ||
102 | ······<ocil:actions> | 84 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 86 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1"> | ||
107 | ···· | 88 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1"> |
89 | ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title> | ||
108 | ······<ocil:actions> | 90 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 92 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_passwordauth_ocil:questionnaire:1"> | ||
113 | ···· | 94 | ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1"> |
95 | ······<ocil:title>Modify·the·System·Login·Banner</ocil:title> | ||
114 | ······<ocil:actions> | 96 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 98 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1"> | ||
119 | ···· | 100 | ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1"> |
101 | ······<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title> | ||
120 | ······<ocil:actions> | 102 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 104 | ······</ocil:actions> |
Max diff block lines reached; 221487/232911 bytes (95.10%) of diff not shown. |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:apple:macos:10.15"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:apple:macos:10.15"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Apple·macOS·10.15</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Apple·macOS·10.15</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-macos1015-cpe-oval.xml">oval:ssg-installed_OS_is_macos1015:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-macos1015-cpe-oval.xml">oval:ssg-installed_OS_is_macos1015:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of | 40 | configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 563, 15 lines modified | Offset 563, 15 lines modified | ||
563 | ··············<xccdf-1.2:check-content-ref·href="ssg-macos1015-ocil.xml"·name="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"/> | 563 | ··············<xccdf-1.2:check-content-ref·href="ssg-macos1015-ocil.xml"·name="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"/> |
564 | ············</xccdf-1.2:check> | 564 | ············</xccdf-1.2:check> |
565 | ··········</xccdf-1.2:Rule> | 565 | ··········</xccdf-1.2:Rule> |
566 | ········</xccdf-1.2:Group> | 566 | ········</xccdf-1.2:Group> |
567 | ······</xccdf-1.2:Group> | 567 | ······</xccdf-1.2:Group> |
568 | ····</xccdf-1.2:Benchmark> | 568 | ····</xccdf-1.2:Benchmark> |
569 | ··</ds:component> | 569 | ··</ds:component> |
570 | ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-oval.xml"·timestamp="2025-0 | 570 | ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-oval.xml"·timestamp="2025-03-01T22:08:00"> |
571 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 571 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
572 | ······<oval-def:generator> | 572 | ······<oval-def:generator> |
573 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 573 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
574 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 574 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
575 | ········<oval:schema_version>5.11</oval:schema_version> | 575 | ········<oval:schema_version>5.11</oval:schema_version> |
576 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 576 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
577 | ······</oval-def:generator> | 577 | ······</oval-def:generator> |
Offset 600, 74 lines modified | Offset 600, 74 lines modified | ||
600 | ··········<ind:filepath>/etc/security/audit_control</ind:filepath> | 600 | ··········<ind:filepath>/etc/security/audit_control</ind:filepath> |
601 | ··········<ind:pattern·operation="pattern·match">^policy:.*,ahlt.*$</ind:pattern> | 601 | ··········<ind:pattern·operation="pattern·match">^policy:.*,ahlt.*$</ind:pattern> |
602 | ··········<ind:instance·datatype="int">1</ind:instance> | 602 | ··········<ind:instance·datatype="int">1</ind:instance> |
603 | ········</ind:textfilecontent54_object> | 603 | ········</ind:textfilecontent54_object> |
604 | ······</oval-def:objects> | 604 | ······</oval-def:objects> |
605 | ····</oval-def:oval_definitions> | 605 | ····</oval-def:oval_definitions> |
606 | ··</ds:component> | 606 | ··</ds:component> |
607 | ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-ocil.xml"·timestamp="2025-0 | 607 | ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
608 | ····<ocil:ocil> | 608 | ····<ocil:ocil> |
609 | ······<ocil:generator> | 609 | ······<ocil:generator> |
610 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 610 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
611 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 611 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
612 | ········<ocil:schema_version>2.0</ocil:schema_version> | 612 | ········<ocil:schema_version>2.0</ocil:schema_version> |
613 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 613 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
614 | ······</ocil:generator> | 614 | ······</ocil:generator> |
615 | ······<ocil:questionnaires> | 615 | ······<ocil:questionnaires> |
616 | ········<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1"> | ||
617 | ··········<ocil:title>Enable·audit·Service</ocil:title> | ||
618 | ··········<ocil:actions> | ||
619 | ············<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref> | ||
620 | ··········</ocil:actions> | ||
621 | ········</ocil:questionnaire> | ||
622 | ········<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"> | 616 | ········<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"> |
623 | ··········<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title> | 617 | ··········<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title> |
624 | ··········<ocil:actions> | 618 | ··········<ocil:actions> |
625 | ············<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref> | 619 | ············<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref> |
626 | ··········</ocil:actions> | 620 | ··········</ocil:actions> |
627 | ········</ocil:questionnaire> | 621 | ········</ocil:questionnaire> |
622 | ········<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1"> | ||
623 | ··········<ocil:title>Enable·audit·Service</ocil:title> | ||
624 | ··········<ocil:actions> | ||
625 | ············<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref> | ||
626 | ··········</ocil:actions> | ||
627 | ········</ocil:questionnaire> | ||
628 | ······</ocil:questionnaires> | 628 | ······</ocil:questionnaires> |
629 | ······<ocil:test_actions> | 629 | ······<ocil:test_actions> |
630 | ········<ocil:boolean_question_test_action·id="ocil:ssg- | 630 | ········<ocil:boolean_question_test_action·id="ocil:ssg-audit_failure_halt_action:testaction:1"·question_ref="ocil:ssg-audit_failure_halt_question:question:1"> |
631 | ··········<ocil:when_true> | 631 | ··········<ocil:when_true> |
632 | ············<ocil:result>PASS</ocil:result> | 632 | ············<ocil:result>PASS</ocil:result> |
633 | ··········</ocil:when_true> | 633 | ··········</ocil:when_true> |
634 | ··········<ocil:when_false> | 634 | ··········<ocil:when_false> |
635 | ············<ocil:result>FAIL</ocil:result> | 635 | ············<ocil:result>FAIL</ocil:result> |
636 | ··········</ocil:when_false> | 636 | ··········</ocil:when_false> |
637 | ········</ocil:boolean_question_test_action> | 637 | ········</ocil:boolean_question_test_action> |
638 | ········<ocil:boolean_question_test_action·id="ocil:ssg- | 638 | ········<ocil:boolean_question_test_action·id="ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1"·question_ref="ocil:ssg-service_com_apple_auditd_enabled_question:question:1"> |
639 | ··········<ocil:when_true> | 639 | ··········<ocil:when_true> |
640 | ············<ocil:result>PASS</ocil:result> | 640 | ············<ocil:result>PASS</ocil:result> |
641 | ··········</ocil:when_true> | 641 | ··········</ocil:when_true> |
642 | ··········<ocil:when_false> | 642 | ··········<ocil:when_false> |
643 | ············<ocil:result>FAIL</ocil:result> | 643 | ············<ocil:result>FAIL</ocil:result> |
644 | ··········</ocil:when_false> | 644 | ··········</ocil:when_false> |
645 | ········</ocil:boolean_question_test_action> | 645 | ········</ocil:boolean_question_test_action> |
646 | ······</ocil:test_actions> | 646 | ······</ocil:test_actions> |
647 | ······<ocil:questions> | 647 | ······<ocil:questions> |
648 | ········<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1"> | ||
649 | ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the | ||
650 | following·command: | ||
651 | $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control | ||
652 | The·output·should·contain·ahlt | ||
653 | ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text> | ||
654 | ········</ocil:boolean_question> | ||
648 | ········<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1"> | 655 | ········<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1"> |
649 | ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the | 656 | ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the |
650 | following·command: | 657 | following·command: |
651 | $·sudo·launchctl·list·com.apple.auditd | 658 | $·sudo·launchctl·list·com.apple.auditd |
652 | The·output·should·return·process·information·for | 659 | The·output·should·return·process·information·for |
653 | com.apple.auditd | 660 | com.apple.auditd |
654 | ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text> | 661 | ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text> |
655 | ········</ocil:boolean_question> | 662 | ········</ocil:boolean_question> |
656 | ········<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1"> | ||
657 | ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the | ||
658 | following·command: | ||
659 | $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control | ||
660 | The·output·should·contain·ahlt | ||
661 | ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text> | ||
662 | ········</ocil:boolean_question> | ||
663 | ······</ocil:questions> | 663 | ······</ocil:questions> |
664 | ····</ocil:ocil> | 664 | ····</ocil:ocil> |
665 | ··</ds:component> | 665 | ··</ds:component> |
666 | ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"·timestamp="2025-0 | 666 | ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"·timestamp="2025-03-01T22:08:00"> |
667 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 667 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
668 | ······<oval-def:generator> | 668 | ······<oval-def:generator> |
669 | ········<oval:product_name>build_cpe.py·from·SCAP·Security·Guide</oval:product_name> | 669 | ········<oval:product_name>build_cpe.py·from·SCAP·Security·Guide</oval:product_name> |
670 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 670 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
671 | ········<oval:schema_version>5.11</oval:schema_version> | 671 | ········<oval:schema_version>5.11</oval:schema_version> |
672 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 672 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
673 | ······</oval-def:generator> | 673 | ······</oval-def:generator> |
Max diff block lines reached; -1/9126 bytes (-0.01%) of diff not shown. |
Offset 3, 56 lines modified | Offset 3, 56 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1"> | ||
11 | ······<ocil:title>Enable·audit·Service</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"> | 10 | ····<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"> |
17 | ······<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title> | 11 | ······<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title> |
18 | ······<ocil:actions> | 12 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref> | 13 | ········<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 14 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1"> | ||
17 | ······<ocil:title>Enable·audit·Service</ocil:title> | ||
18 | ······<ocil:actions> | ||
19 | ········<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref> | ||
20 | ······</ocil:actions> | ||
21 | ····</ocil:questionnaire> | ||
22 | ··</ocil:questionnaires> | 22 | ··</ocil:questionnaires> |
23 | ··<ocil:test_actions> | 23 | ··<ocil:test_actions> |
24 | ····<ocil:boolean_question_test_action·id="ocil:ssg- | 24 | ····<ocil:boolean_question_test_action·id="ocil:ssg-audit_failure_halt_action:testaction:1"·question_ref="ocil:ssg-audit_failure_halt_question:question:1"> |
25 | ······<ocil:when_true> | 25 | ······<ocil:when_true> |
26 | ········<ocil:result>PASS</ocil:result> | 26 | ········<ocil:result>PASS</ocil:result> |
27 | ······</ocil:when_true> | 27 | ······</ocil:when_true> |
28 | ······<ocil:when_false> | 28 | ······<ocil:when_false> |
29 | ········<ocil:result>FAIL</ocil:result> | 29 | ········<ocil:result>FAIL</ocil:result> |
30 | ······</ocil:when_false> | 30 | ······</ocil:when_false> |
31 | ····</ocil:boolean_question_test_action> | 31 | ····</ocil:boolean_question_test_action> |
32 | ····<ocil:boolean_question_test_action·id="ocil:ssg- | 32 | ····<ocil:boolean_question_test_action·id="ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1"·question_ref="ocil:ssg-service_com_apple_auditd_enabled_question:question:1"> |
33 | ······<ocil:when_true> | 33 | ······<ocil:when_true> |
34 | ········<ocil:result>PASS</ocil:result> | 34 | ········<ocil:result>PASS</ocil:result> |
35 | ······</ocil:when_true> | 35 | ······</ocil:when_true> |
36 | ······<ocil:when_false> | 36 | ······<ocil:when_false> |
37 | ········<ocil:result>FAIL</ocil:result> | 37 | ········<ocil:result>FAIL</ocil:result> |
38 | ······</ocil:when_false> | 38 | ······</ocil:when_false> |
39 | ····</ocil:boolean_question_test_action> | 39 | ····</ocil:boolean_question_test_action> |
40 | ··</ocil:test_actions> | 40 | ··</ocil:test_actions> |
41 | ··<ocil:questions> | 41 | ··<ocil:questions> |
42 | ····<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1"> | ||
43 | ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the | ||
44 | following·command: | ||
45 | $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control | ||
46 | The·output·should·contain·ahlt | ||
47 | ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text> | ||
48 | ····</ocil:boolean_question> | ||
42 | ····<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1"> | 49 | ····<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1"> |
43 | ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the | 50 | ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the |
44 | following·command: | 51 | following·command: |
45 | $·sudo·launchctl·list·com.apple.auditd | 52 | $·sudo·launchctl·list·com.apple.auditd |
46 | The·output·should·return·process·information·for | 53 | The·output·should·return·process·information·for |
47 | com.apple.auditd | 54 | com.apple.auditd |
48 | ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text> | 55 | ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text> |
49 | ····</ocil:boolean_question> | 56 | ····</ocil:boolean_question> |
50 | ····<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1"> | ||
51 | ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the | ||
52 | following·command: | ||
53 | $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control | ||
54 | The·output·should·contain·ahlt | ||
55 | ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text> | ||
56 | ····</ocil:boolean_question> | ||
57 | ··</ocil:questions> | 57 | ··</ocil:questions> |
58 | </ocil:ocil> | 58 | </ocil:ocil> |
Offset 19, 15 lines modified | Offset 19, 15 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.1"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.1"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.10"> | 32 | ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.10"> |
33 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4.10</cpe-dict:title> | 33 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4.10</cpe-dict:title> |
Offset 111, 15 lines modified | Offset 111, 15 lines modified | ||
111 | ······</cpe-dict:cpe-item> | 111 | ······</cpe-dict:cpe-item> |
112 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:openshift_container_platform_node:4"> | 112 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:openshift_container_platform_node:4"> |
113 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4·Node</cpe-dict:title> | 113 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4·Node</cpe-dict:title> |
114 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4_node:def:1</cpe-dict:check> | 114 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4_node:def:1</cpe-dict:check> |
115 | ······</cpe-dict:cpe-item> | 115 | ······</cpe-dict:cpe-item> |
116 | ····</cpe-dict:cpe-list> | 116 | ····</cpe-dict:cpe-list> |
117 | ··</ds:component> | 117 | ··</ds:component> |
118 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-xccdf.xml"·timestamp="2025-0 | 118 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
119 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OCP-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 119 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OCP-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
120 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 120 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
121 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container·Platform·4</xccdf-1.2:title> | 121 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container·Platform·4</xccdf-1.2:title> |
122 | ······<xccdf-1.2:description> | 122 | ······<xccdf-1.2:description> |
123 | ········This·guide·presents·a·catalog·of·security-relevant | 123 | ········This·guide·presents·a·catalog·of·security-relevant |
124 | configuration·settings·for·Red·Hat·OpenShift·Container·Platform·4.·It·is·a·rendering·of | 124 | configuration·settings·for·Red·Hat·OpenShift·Container·Platform·4.·It·is·a·rendering·of |
125 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 125 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 22582, 15 lines modified | Offset 22582, 15 lines modified | ||
22582 | ··············<xccdf-1.2:check-content-ref·href="ssg-ocp4-ocil.xml"·name="ocil:ssg-file_permissions_worker_service_ocil:questionnaire:1"/> | 22582 | ··············<xccdf-1.2:check-content-ref·href="ssg-ocp4-ocil.xml"·name="ocil:ssg-file_permissions_worker_service_ocil:questionnaire:1"/> |
22583 | ············</xccdf-1.2:check> | 22583 | ············</xccdf-1.2:check> |
22584 | ··········</xccdf-1.2:Rule> | 22584 | ··········</xccdf-1.2:Rule> |
22585 | ········</xccdf-1.2:Group> | 22585 | ········</xccdf-1.2:Group> |
22586 | ······</xccdf-1.2:Group> | 22586 | ······</xccdf-1.2:Group> |
22587 | ····</xccdf-1.2:Benchmark> | 22587 | ····</xccdf-1.2:Benchmark> |
22588 | ··</ds:component> | 22588 | ··</ds:component> |
22589 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-oval.xml"·timestamp="2025-0 | 22589 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-oval.xml"·timestamp="2025-03-01T22:08:00"> |
22590 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 22590 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
22591 | ······<oval-def:generator> | 22591 | ······<oval-def:generator> |
22592 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 22592 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
22593 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 22593 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
22594 | ········<oval:schema_version>5.11</oval:schema_version> | 22594 | ········<oval:schema_version>5.11</oval:schema_version> |
22595 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 22595 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
22596 | ······</oval-def:generator> | 22596 | ······</oval-def:generator> |
Offset 34382, 5557 lines modified | Offset 34382, 5382 lines modified | ||
34382 | ············<oval-def:variable_component·var_ref="oval:ssg-ocp_data_root:var:1"/> | 34382 | ············<oval-def:variable_component·var_ref="oval:ssg-ocp_data_root:var:1"/> |
34383 | ············<oval-def:literal_component>/apis/apps/v1/namespaces/openshift-ingress/deployments/router-default#aa685c2fe85cfde2ec878952fdd5e72b0824bdaccd1063efcfc29fea8137840c</oval-def:literal_component> | 34383 | ············<oval-def:literal_component>/apis/apps/v1/namespaces/openshift-ingress/deployments/router-default#aa685c2fe85cfde2ec878952fdd5e72b0824bdaccd1063efcfc29fea8137840c</oval-def:literal_component> |
34384 | ··········</oval-def:concat> | 34384 | ··········</oval-def:concat> |
34385 | ········</oval-def:local_variable> | 34385 | ········</oval-def:local_variable> |
34386 | ······</oval-def:variables> | 34386 | ······</oval-def:variables> |
34387 | ····</oval-def:oval_definitions> | 34387 | ····</oval-def:oval_definitions> |
34388 | ··</ds:component> | 34388 | ··</ds:component> |
34389 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-ocil.xml"·timestamp="2025-0 | 34389 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
34390 | ····<ocil:ocil> | 34390 | ····<ocil:ocil> |
34391 | ······<ocil:generator> | 34391 | ······<ocil:generator> |
34392 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 34392 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
34393 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 34393 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
34394 | ········<ocil:schema_version>2.0</ocil:schema_version> | 34394 | ········<ocil:schema_version>2.0</ocil:schema_version> |
34395 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 34395 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
34396 | ······</ocil:generator> | 34396 | ······</ocil:generator> |
34397 | ······<ocil:questionnaires> | 34397 | ······<ocil:questionnaires> |
34398 | ········<ocil:questionnaire·id="ocil:ssg- | 34398 | ········<ocil:questionnaire·id="ocil:ssg-kube_descheduler_operator_exists_ocil:questionnaire:1"> |
34399 | ··········<ocil:title> | 34399 | ··········<ocil:title>Ensure·that·the·Kube·Descheduler·operator·is·deployed</ocil:title> |
34400 | ··········<ocil:actions> | 34400 | ··········<ocil:actions> |
34401 | ············<ocil:test_action_ref>ocil:ssg- | 34401 | ············<ocil:test_action_ref>ocil:ssg-kube_descheduler_operator_exists_action:testaction:1</ocil:test_action_ref> |
34402 | ··········</ocil:actions> | 34402 | ··········</ocil:actions> |
34403 | ········</ocil:questionnaire> | 34403 | ········</ocil:questionnaire> |
34404 | ········<ocil:questionnaire·id="ocil:ssg-file_ | 34404 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_ocp_audit_ocil:questionnaire:1"> |
34405 | ··········<ocil:title>O | 34405 | ··········<ocil:title>OpenShift·Audit·Logs·Must·Have·Mode·0600</ocil:title> |
34406 | ··········<ocil:actions> | 34406 | ··········<ocil:actions> |
34407 | ············<ocil:test_action_ref>ocil:ssg-file_ | 34407 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_ocp_audit_action:testaction:1</ocil:test_action_ref> |
34408 | ··········</ocil:actions> | 34408 | ··········</ocil:actions> |
34409 | ········</ocil:questionnaire> | 34409 | ········</ocil:questionnaire> |
34410 | ········<ocil:questionnaire·id="ocil:ssg- | 34410 | ········<ocil:questionnaire·id="ocil:ssg-api_server_token_auth_ocil:questionnaire:1"> |
34411 | ··········<ocil:title> | 34411 | ··········<ocil:title>Disable·Token-based·Authentication</ocil:title> |
34412 | ··········<ocil:actions> | 34412 | ··········<ocil:actions> |
34413 | ············<ocil:test_action_ref>ocil:ssg- | 34413 | ············<ocil:test_action_ref>ocil:ssg-api_server_token_auth_action:testaction:1</ocil:test_action_ref> |
34414 | ··········</ocil:actions> | 34414 | ··········</ocil:actions> |
34415 | ········</ocil:questionnaire> | 34415 | ········</ocil:questionnaire> |
34416 | ········<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_soft_imagefs_available_ocil:questionnaire:1"> | ||
34417 | ········ | 34416 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_service_ocil:questionnaire:1"> |
34417 | ··········<ocil:title>Verify·Permissions·on·the·OpenShift·Node·Service·File</ocil:title> | ||
34418 | ··········<ocil:actions> | 34418 | ··········<ocil:actions> |
34419 | ············<ocil:test_action_ref>ocil:ssg- | 34419 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_worker_service_action:testaction:1</ocil:test_action_ref> |
34420 | ··········</ocil:actions> | 34420 | ··········</ocil:actions> |
34421 | ········</ocil:questionnaire> | 34421 | ········</ocil:questionnaire> |
34422 | ········<ocil:questionnaire·id="ocil:ssg-file_ | 34422 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_multus_conf_ocil:questionnaire:1"> |
34423 | ··········<ocil:title> | 34423 | ··········<ocil:title>Verify·User·Who·Owns·The·OpenShift·Multus·Container·Network·Interface·Plugin·Files</ocil:title> |
34424 | ··········<ocil:actions> | 34424 | ··········<ocil:actions> |
34425 | ············<ocil:test_action_ref>ocil:ssg-file_ | 34425 | ············<ocil:test_action_ref>ocil:ssg-file_owner_multus_conf_action:testaction:1</ocil:test_action_ref> |
34426 | ··········</ocil:actions> | 34426 | ··········</ocil:actions> |
34427 | ········</ocil:questionnaire> | 34427 | ········</ocil:questionnaire> |
34428 | ········<ocil:questionnaire·id="ocil:ssg- | 34428 | ········<ocil:questionnaire·id="ocil:ssg-etcd_peer_auto_tls_ocil:questionnaire:1"> |
34429 | ··········<ocil:title> | 34429 | ··········<ocil:title>Disable·etcd·Peer·Self-Signed·Certificates</ocil:title> |
34430 | ··········<ocil:actions> | 34430 | ··········<ocil:actions> |
34431 | ············<ocil:test_action_ref>ocil:ssg- | 34431 | ············<ocil:test_action_ref>ocil:ssg-etcd_peer_auto_tls_action:testaction:1</ocil:test_action_ref> |
34432 | ··········</ocil:actions> | 34432 | ··········</ocil:actions> |
34433 | ········</ocil:questionnaire> | 34433 | ········</ocil:questionnaire> |
34434 | ········<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_hard_memory_available_ocil:questionnaire:1"> | ||
34435 | ········ | 34434 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_etcd_data_dir_ocil:questionnaire:1"> |
34435 | ··········<ocil:title>Verify·User·Who·Owns·The·Etcd·Database·Directory</ocil:title> | ||
34436 | ··········<ocil:actions> | 34436 | ··········<ocil:actions> |
34437 | ············<ocil:test_action_ref>ocil:ssg- | 34437 | ············<ocil:test_action_ref>ocil:ssg-file_owner_etcd_data_dir_action:testaction:1</ocil:test_action_ref> |
34438 | ··········</ocil:actions> | 34438 | ··········</ocil:actions> |
34439 | ········</ocil:questionnaire> | 34439 | ········</ocil:questionnaire> |
34440 | ········<ocil:questionnaire·id="ocil:ssg- | 34440 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_ip_allocations_ocil:questionnaire:1"> |
34441 | ··········<ocil:title> | 34441 | ··········<ocil:title>Verify·User·Who·Owns·The·OpenShift·SDN·Container·Network·Interface·Plugin·IP·Address·Allocations</ocil:title> |
34442 | ··········<ocil:actions> | 34442 | ··········<ocil:actions> |
34443 | ············<ocil:test_action_ref>ocil:ssg- | 34443 | ············<ocil:test_action_ref>ocil:ssg-file_owner_ip_allocations_action:testaction:1</ocil:test_action_ref> |
34444 | ··········</ocil:actions> | 34444 | ··········</ocil:actions> |
34445 | ········</ocil:questionnaire> | 34445 | ········</ocil:questionnaire> |
34446 | ········<ocil:questionnaire·id="ocil:ssg- | 34446 | ········<ocil:questionnaire·id="ocil:ssg-etcd_check_cipher_suite_ocil:questionnaire:1"> |
34447 | ··········<ocil:title> | 34447 | ··········<ocil:title>Ensure·ETCD·has·correct·cipher·suite</ocil:title> |
34448 | ··········<ocil:actions> | 34448 | ··········<ocil:actions> |
34449 | ············<ocil:test_action_ref>ocil:ssg- | 34449 | ············<ocil:test_action_ref>ocil:ssg-etcd_check_cipher_suite_action:testaction:1</ocil:test_action_ref> |
34450 | ··········</ocil:actions> | 34450 | ··········</ocil:actions> |
34451 | ········</ocil:questionnaire> | 34451 | ········</ocil:questionnaire> |
34452 | ········<ocil:questionnaire·id="ocil:ssg- | 34452 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_kube_controller_manager_ocil:questionnaire:1"> |
34453 | ··········<ocil:title> | 34453 | ··········<ocil:title>Verify·Permissions·on·the·Kubernetes·Controller·Manager·Pod·Specification·File</ocil:title> |
34454 | ··········<ocil:actions> | 34454 | ··········<ocil:actions> |
34455 | ············<ocil:test_action_ref>ocil:ssg- | 34455 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_kube_controller_manager_action:testaction:1</ocil:test_action_ref> |
34456 | ··········</ocil:actions> | 34456 | ··········</ocil:actions> |
34457 | ········</ocil:questionnaire> | 34457 | ········</ocil:questionnaire> |
34458 | ········<ocil:questionnaire·id="ocil:ssg- | 34458 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_lib_etcd_ocil:questionnaire:1"> |
Max diff block lines reached; 894952/907488 bytes (98.62%) of diff not shown. |
Offset 3, 5548 lines modified | Offset 3, 5373 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg- | 10 | ····<ocil:questionnaire·id="ocil:ssg-kube_descheduler_operator_exists_ocil:questionnaire:1"> |
11 | ······<ocil:title> | 11 | ······<ocil:title>Ensure·that·the·Kube·Descheduler·operator·is·deployed</ocil:title> |
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-kube_descheduler_operator_exists_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg-file_ | 16 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_ocp_audit_ocil:questionnaire:1"> |
17 | ······<ocil:title>O | 17 | ······<ocil:title>OpenShift·Audit·Logs·Must·Have·Mode·0600</ocil:title> |
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg-file_ | 19 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_ocp_audit_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-api_server_token_auth_ocil:questionnaire:1"> |
23 | ······<ocil:title> | 23 | ······<ocil:title>Disable·Token-based·Authentication</ocil:title> |
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-api_server_token_auth_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_soft_imagefs_available_ocil:questionnaire:1"> | ||
29 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_service_ocil:questionnaire:1"> |
29 | ······<ocil:title>Verify·Permissions·on·the·OpenShift·Node·Service·File</ocil:title> | ||
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_worker_service_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-file_ | 34 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_multus_conf_ocil:questionnaire:1"> |
35 | ······<ocil:title> | 35 | ······<ocil:title>Verify·User·Who·Owns·The·OpenShift·Multus·Container·Network·Interface·Plugin·Files</ocil:title> |
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg-file_ | 37 | ········<ocil:test_action_ref>ocil:ssg-file_owner_multus_conf_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 40 | ····<ocil:questionnaire·id="ocil:ssg-etcd_peer_auto_tls_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 41 | ······<ocil:title>Disable·etcd·Peer·Self-Signed·Certificates</ocil:title> |
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-etcd_peer_auto_tls_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_hard_memory_available_ocil:questionnaire:1"> | ||
47 | ···· | 46 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_etcd_data_dir_ocil:questionnaire:1"> |
47 | ······<ocil:title>Verify·User·Who·Owns·The·Etcd·Database·Directory</ocil:title> | ||
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-file_owner_etcd_data_dir_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 52 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_ip_allocations_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 53 | ······<ocil:title>Verify·User·Who·Owns·The·OpenShift·SDN·Container·Network·Interface·Plugin·IP·Address·Allocations</ocil:title> |
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-file_owner_ip_allocations_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-etcd_check_cipher_suite_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 59 | ······<ocil:title>Ensure·ETCD·has·correct·cipher·suite</ocil:title> |
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-etcd_check_cipher_suite_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_kube_controller_manager_ocil:questionnaire:1"> |
65 | ······<ocil:title> | 65 | ······<ocil:title>Verify·Permissions·on·the·Kubernetes·Controller·Manager·Pod·Specification·File</ocil:title> |
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_kube_controller_manager_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_lib_etcd_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 71 | ······<ocil:title>Verify·User·Who·Owns·The·OpenShift·etcd·Data·Directory</ocil:title> |
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-file_owner_var_lib_etcd_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg- | 76 | ····<ocil:questionnaire·id="ocil:ssg-master_taint_noschedule_ocil:questionnaire:1"> |
77 | ······<ocil:title> | 77 | ······<ocil:title>Verify·that·Control·Plane·Nodes·are·not·schedulable·for·workloads</ocil:title> |
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-master_taint_noschedule_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_o | 82 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_kube_audit_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 83 | ······<ocil:title>Kubernetes·Audit·Logs·Must·Have·Mode·0600</ocil:title> |
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_o | 85 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_kube_audit_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg- | 88 | ····<ocil:questionnaire·id="ocil:ssg-audit_profile_set_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 89 | ······<ocil:title>Ensure·that·the·cluster's·audit·profile·is·properly·set</ocil:title> |
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-audit_profile_set_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-resource_requests_limits_in_deployment_ocil:questionnaire:1"> | ||
95 | ···· | 94 | ····<ocil:questionnaire·id="ocil:ssg-ingress_controller_certificate_ocil:questionnaire:1"> |
95 | ······<ocil:title>Ensure·that·the·default·Ingress·certificate·has·been·replaced</ocil:title> | ||
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-ingress_controller_certificate_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-etcd_key_file_ocil:questionnaire:1"> |
101 | ······<ocil:title> | 101 | ······<ocil:title>Ensure·That·The·etcd·Key·File·Is·Correctly·Set</ocil:title> |
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-etcd_key_file_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-cluster_version_operator_exists_ocil:questionnaire:1"> | ||
107 | ···· | 106 | ····<ocil:questionnaire·id="ocil:ssg-scc_limit_ipc_namespace_ocil:questionnaire:1"> |
107 | ······<ocil:title>Limit·Access·to·the·Host·IPC·Namespace</ocil:title> | ||
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-scc_limit_ipc_namespace_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-accounts_restrict_service_account_tokens_ocil:questionnaire:1"> | ||
113 | ···· | 112 | ····<ocil:questionnaire·id="ocil:ssg-resource_requests_limits_in_daemonset_ocil:questionnaire:1"> |
113 | ······<ocil:title>Ensure·that·all·daemonsets·has·resource·limits</ocil:title> | ||
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-resource_requests_limits_in_daemonset_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-rbac_wildcard_use_ocil:questionnaire:1"> | ||
119 | ···· | 118 | ····<ocil:questionnaire·id="ocil:ssg-scansetting_has_autoapplyremediations_ocil:questionnaire:1"> |
119 | ······<ocil:title>Enable·AutoApplyRemediation·for·at·least·One·ScanSetting</ocil:title> | ||
120 | ······<ocil:actions> | 120 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg- | 121 | ········<ocil:test_action_ref>ocil:ssg-scansetting_has_autoapplyremediations_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 122 | ······</ocil:actions> |
123 | ····</ocil:questionnaire> | 123 | ····</ocil:questionnaire> |
Max diff block lines reached; 856241/869455 bytes (98.48%) of diff not shown. |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:10"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:10"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·10</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·10</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml">oval:ssg-installed_OS_is_ol10:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml">oval:ssg-installed_OS_is_ol10:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·10</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·10</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Oracle·Linux·10.·It·is·a·rendering·of | 40 | configuration·settings·for·Oracle·Linux·10.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 194138, 15 lines modified | Offset 194138, 15 lines modified | ||
194138 | ··············<xccdf-1.2:check-content-ref·href="ssg-ol10-ocil.xml"·name="ocil:ssg-audit_access_success_ocil:questionnaire:1"/> | 194138 | ··············<xccdf-1.2:check-content-ref·href="ssg-ol10-ocil.xml"·name="ocil:ssg-audit_access_success_ocil:questionnaire:1"/> |
194139 | ············</xccdf-1.2:check> | 194139 | ············</xccdf-1.2:check> |
194140 | ··········</xccdf-1.2:Rule> | 194140 | ··········</xccdf-1.2:Rule> |
194141 | ········</xccdf-1.2:Group> | 194141 | ········</xccdf-1.2:Group> |
194142 | ······</xccdf-1.2:Group> | 194142 | ······</xccdf-1.2:Group> |
194143 | ····</xccdf-1.2:Benchmark> | 194143 | ····</xccdf-1.2:Benchmark> |
194144 | ··</ds:component> | 194144 | ··</ds:component> |
194145 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-oval.xml"·timestamp="2025-0 | 194145 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-oval.xml"·timestamp="2025-03-01T22:08:00"> |
194146 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 194146 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
194147 | ······<oval-def:generator> | 194147 | ······<oval-def:generator> |
194148 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 194148 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
194149 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 194149 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
194150 | ········<oval:schema_version>5.11</oval:schema_version> | 194150 | ········<oval:schema_version>5.11</oval:schema_version> |
194151 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 194151 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
194152 | ······</oval-def:generator> | 194152 | ······</oval-def:generator> |
Offset 237580, 6337 lines modified | Offset 237580, 6337 lines modified | ||
237580 | ············</oval-def:arithmetic> | 237580 | ············</oval-def:arithmetic> |
237581 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 237581 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
237582 | ··········</oval-def:arithmetic> | 237582 | ··········</oval-def:arithmetic> |
237583 | ········</oval-def:local_variable> | 237583 | ········</oval-def:local_variable> |
237584 | ······</oval-def:variables> | 237584 | ······</oval-def:variables> |
237585 | ····</oval-def:oval_definitions> | 237585 | ····</oval-def:oval_definitions> |
237586 | ··</ds:component> | 237586 | ··</ds:component> |
237587 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-ocil.xml"·timestamp="2025-0 | 237587 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
237588 | ····<ocil:ocil> | 237588 | ····<ocil:ocil> |
237589 | ······<ocil:generator> | 237589 | ······<ocil:generator> |
237590 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 237590 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
237591 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 237591 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
237592 | ········<ocil:schema_version>2.0</ocil:schema_version> | 237592 | ········<ocil:schema_version>2.0</ocil:schema_version> |
237593 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 237593 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
237594 | ······</ocil:generator> | 237594 | ······</ocil:generator> |
237595 | ······<ocil:questionnaires> | 237595 | ······<ocil:questionnaires> |
237596 | ········<ocil:questionnaire·id="ocil:ssg- | 237596 | ········<ocil:questionnaire·id="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1"> |
237597 | ··········<ocil:title> | 237597 | ··········<ocil:title>Verify·Root·Has·A·Primary·GID·0</ocil:title> |
237598 | ··········<ocil:actions> | 237598 | ··········<ocil:actions> |
237599 | ············<ocil:test_action_ref>ocil:ssg- | 237599 | ············<ocil:test_action_ref>ocil:ssg-accounts_root_gid_zero_action:testaction:1</ocil:test_action_ref> |
237600 | ··········</ocil:actions> | 237600 | ··········</ocil:actions> |
237601 | ········</ocil:questionnaire> | 237601 | ········</ocil:questionnaire> |
237602 | ········<ocil:questionnaire·id="ocil:ssg- | 237602 | ········<ocil:questionnaire·id="ocil:ssg-chronyd_client_only_ocil:questionnaire:1"> |
237603 | ··········<ocil:title> | 237603 | ··········<ocil:title>Disable·chrony·daemon·from·acting·as·server</ocil:title> |
237604 | ··········<ocil:actions> | 237604 | ··········<ocil:actions> |
237605 | ············<ocil:test_action_ref>ocil:ssg- | 237605 | ············<ocil:test_action_ref>ocil:ssg-chronyd_client_only_action:testaction:1</ocil:test_action_ref> |
237606 | ··········</ocil:actions> | 237606 | ··········</ocil:actions> |
237607 | ········</ocil:questionnaire> | 237607 | ········</ocil:questionnaire> |
237608 | ········<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_stig_ocil:questionnaire:1"> | ||
237609 | ········ | 237608 | ········<ocil:questionnaire·id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1"> |
237609 | ··········<ocil:title>Ensure·gnutls-utils·is·installed</ocil:title> | ||
237610 | ··········<ocil:actions> | 237610 | ··········<ocil:actions> |
237611 | ············<ocil:test_action_ref>ocil:ssg- | 237611 | ············<ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref> |
237612 | ··········</ocil:actions> | 237612 | ··········</ocil:actions> |
237613 | ········</ocil:questionnaire> | 237613 | ········</ocil:questionnaire> |
237614 | ········<ocil:questionnaire·id="ocil:ssg- | 237614 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_strict_module_rwx_ocil:questionnaire:1"> |
237615 | ··········<ocil:title> | 237615 | ··········<ocil:title>Make·the·module·text·and·rodata·read-only</ocil:title> |
237616 | ··········<ocil:actions> | 237616 | ··········<ocil:actions> |
237617 | ············<ocil:test_action_ref>ocil:ssg- | 237617 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_strict_module_rwx_action:testaction:1</ocil:test_action_ref> |
237618 | ··········</ocil:actions> | 237618 | ··········</ocil:actions> |
237619 | ········</ocil:questionnaire> | 237619 | ········</ocil:questionnaire> |
237620 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1"> | ||
237621 | ········ | 237620 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"> |
237621 | ··········<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title> | ||
237622 | ··········<ocil:actions> | 237622 | ··········<ocil:actions> |
237623 | ············<ocil:test_action_ref>ocil:ssg- | 237623 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref> |
237624 | ··········</ocil:actions> | 237624 | ··········</ocil:actions> |
237625 | ········</ocil:questionnaire> | 237625 | ········</ocil:questionnaire> |
237626 | ········<ocil:questionnaire·id="ocil:ssg- | 237626 | ········<ocil:questionnaire·id="ocil:ssg-set_firewalld_default_zone_ocil:questionnaire:1"> |
237627 | ··········<ocil:title> | 237627 | ··········<ocil:title>Set·Default·firewalld·Zone·for·Incoming·Packets</ocil:title> |
237628 | ··········<ocil:actions> | 237628 | ··········<ocil:actions> |
237629 | ············<ocil:test_action_ref>ocil:ssg- | 237629 | ············<ocil:test_action_ref>ocil:ssg-set_firewalld_default_zone_action:testaction:1</ocil:test_action_ref> |
237630 | ··········</ocil:actions> | 237630 | ··········</ocil:actions> |
237631 | ········</ocil:questionnaire> | 237631 | ········</ocil:questionnaire> |
237632 | ········<ocil:questionnaire·id="ocil:ssg- | 237632 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1"> |
237633 | ··········<ocil:title> | 237633 | ··········<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title> |
237634 | ··········<ocil:actions> | 237634 | ··········<ocil:actions> |
237635 | ············<ocil:test_action_ref>ocil:ssg- | 237635 | ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref> |
237636 | ··········</ocil:actions> | 237636 | ··········</ocil:actions> |
237637 | ········</ocil:questionnaire> | 237637 | ········</ocil:questionnaire> |
237638 | ········<ocil:questionnaire·id="ocil:ssg-mount_option_nodev_removable_partitions_ocil:questionnaire:1"> | ||
237639 | ········ | 237638 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1"> |
237639 | ··········<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title> | ||
237640 | ··········<ocil:actions> | 237640 | ··········<ocil:actions> |
237641 | ············<ocil:test_action_ref>ocil:ssg- | 237641 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref> |
237642 | ··········</ocil:actions> | 237642 | ··········</ocil:actions> |
237643 | ········</ocil:questionnaire> | 237643 | ········</ocil:questionnaire> |
237644 | ········<ocil:questionnaire·id="ocil:ssg- | 237644 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1"> |
237645 | ··········<ocil:title> | 237645 | ··········<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title> |
237646 | ··········<ocil:actions> | 237646 | ··········<ocil:actions> |
237647 | ············<ocil:test_action_ref>ocil:ssg- | 237647 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref> |
237648 | ··········</ocil:actions> | 237648 | ··········</ocil:actions> |
237649 | ········</ocil:questionnaire> | 237649 | ········</ocil:questionnaire> |
237650 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_ocil:questionnaire:1"> | ||
237651 | ········ | 237650 | ········<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1"> |
237651 | ··········<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title> | ||
237652 | ··········<ocil:actions> | 237652 | ··········<ocil:actions> |
237653 | ············<ocil:test_action_ref>ocil:ssg- | 237653 | ············<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref> |
237654 | ··········</ocil:actions> | 237654 | ··········</ocil:actions> |
237655 | ········</ocil:questionnaire> | 237655 | ········</ocil:questionnaire> |
237656 | ········<ocil:questionnaire·id="ocil:ssg- | 237656 | ········<ocil:questionnaire·id="ocil:ssg-networkmanager_dns_mode_ocil:questionnaire:1"> |
237657 | ··········<ocil:title> | 237657 | ··········<ocil:title>NetworkManager·DNS·Mode·Must·Be·Must·Configured</ocil:title> |
237658 | ··········<ocil:actions> | 237658 | ··········<ocil:actions> |
237659 | ············<ocil:test_action_ref>ocil:ssg- | 237659 | ············<ocil:test_action_ref>ocil:ssg-networkmanager_dns_mode_action:testaction:1</ocil:test_action_ref> |
237660 | ··········</ocil:actions> | 237660 | ··········</ocil:actions> |
237661 | ········</ocil:questionnaire> | 237661 | ········</ocil:questionnaire> |
237662 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1"> | ||
Max diff block lines reached; 1888034/1900229 bytes (99.36%) of diff not shown. |
Offset 3, 6328 lines modified | Offset 3, 6328 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg- | 10 | ····<ocil:questionnaire·id="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1"> |
11 | ······<ocil:title> | 11 | ······<ocil:title>Verify·Root·Has·A·Primary·GID·0</ocil:title> |
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-accounts_root_gid_zero_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg- | 16 | ····<ocil:questionnaire·id="ocil:ssg-chronyd_client_only_ocil:questionnaire:1"> |
17 | ······<ocil:title> | 17 | ······<ocil:title>Disable·chrony·daemon·from·acting·as·server</ocil:title> |
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-chronyd_client_only_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_stig_ocil:questionnaire:1"> | ||
23 | ···· | 22 | ····<ocil:questionnaire·id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1"> |
23 | ······<ocil:title>Ensure·gnutls-utils·is·installed</ocil:title> | ||
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1"> | ||
29 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_strict_module_rwx_ocil:questionnaire:1"> |
29 | ······<ocil:title>Make·the·module·text·and·rodata·read-only</ocil:title> | ||
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_strict_module_rwx_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1"> | ||
35 | ···· | 34 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"> |
35 | ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title> | ||
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 40 | ····<ocil:questionnaire·id="ocil:ssg-set_firewalld_default_zone_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 41 | ······<ocil:title>Set·Default·firewalld·Zone·for·Incoming·Packets</ocil:title> |
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-set_firewalld_default_zone_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg- | 46 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1"> |
47 | ······<ocil:title> | 47 | ······<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title> |
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_nodev_removable_partitions_ocil:questionnaire:1"> | ||
53 | ···· | 52 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1"> |
53 | ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title> | ||
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 59 | ······<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title> |
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_ocil:questionnaire:1"> | ||
65 | ···· | 64 | ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1"> |
65 | ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title> | ||
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-networkmanager_dns_mode_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 71 | ······<ocil:title>NetworkManager·DNS·Mode·Must·Be·Must·Configured</ocil:title> |
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-networkmanager_dns_mode_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1"> | ||
77 | ···· | 76 | ····<ocil:questionnaire·id="ocil:ssg-service_sssd_enabled_ocil:questionnaire:1"> |
77 | ······<ocil:title>Enable·the·SSSD·Service</ocil:title> | ||
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-service_sssd_enabled_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_session_idle_user_locks_ocil:questionnaire:1"> | ||
83 | ···· | 82 | ····<ocil:questionnaire·id="ocil:ssg-service_kdump_disabled_ocil:questionnaire:1"> |
83 | ······<ocil:title>Disable·KDump·Kernel·Crash·Analyzer·(kdump)</ocil:title> | ||
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-service_kdump_disabled_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg- | 88 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_chsh_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 89 | ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·chsh</ocil:title> |
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_chsh_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_suid_ocil:questionnaire:1"> | ||
95 | ···· | 94 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_ocil:questionnaire:1"> |
95 | ······<ocil:title>Limit·Password·Reuse:·password-auth</ocil:title> | ||
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_yama_ptrace_scope_ocil:questionnaire:1"> | ||
101 | ···· | 100 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_noexec_ocil:questionnaire:1"> |
101 | ······<ocil:title>Add·noexec·Option·to·/boot</ocil:title> | ||
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_noexec_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-file_ | 106 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_sudoers_ocil:questionnaire:1"> |
107 | ······<ocil:title>Verify· | 107 | ······<ocil:title>Verify·Permissions·On·/etc/sudoers·File</ocil:title> |
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg-file_ | 109 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_sudoers_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-s | 112 | ····<ocil:questionnaire·id="ocil:ssg-sudoers_explicit_command_args_ocil:questionnaire:1"> |
113 | ······<ocil:title>E | 113 | ······<ocil:title>Explicit·arguments·in·sudo·specifications</ocil:title> |
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg-s | 115 | ········<ocil:test_action_ref>ocil:ssg-sudoers_explicit_command_args_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1"> | ||
119 | ···· | 118 | ····<ocil:questionnaire·id="ocil:ssg-directory_groupowner_etc_selinux_ocil:questionnaire:1"> |
119 | ······<ocil:title>Verify·Group·Who·Owns·/etc/selinux·Directory</ocil:title> | ||
Max diff block lines reached; 1806750/1819121 bytes (99.32%) of diff not shown. |
Offset 21, 23 lines modified | Offset 21, 23 lines modified | ||
21 | ····<ds:checks> | 21 | ····<ds:checks> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-oval.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-oval.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-ocil.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-ocil.xml"/> |
24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-cpe-oval.xml"/> | 24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-cpe-oval.xml"/> |
25 | ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol7.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol7.xml.bz2"/> | 25 | ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol7.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol7.xml.bz2"/> |
26 | ····</ds:checks> | 26 | ····</ds:checks> |
27 | ··</ds:data-stream> | 27 | ··</ds:data-stream> |
28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-cpe-dictionary.xml"·timestamp="2025-0 | 28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
30 | ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:7"> | 30 | ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:7"> |
31 | ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·7</cpe-dict:title> | 31 | ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·7</cpe-dict:title> |
32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml">oval:ssg-installed_OS_is_ol7:def:1</cpe-dict:check> | 32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml">oval:ssg-installed_OS_is_ol7:def:1</cpe-dict:check> |
33 | ······</cpe-dict:cpe-item> | 33 | ······</cpe-dict:cpe-item> |
34 | ····</cpe-dict:cpe-list> | 34 | ····</cpe-dict:cpe-list> |
35 | ··</ds:component> | 35 | ··</ds:component> |
36 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-xccdf.xml"·timestamp="2025-0 | 36 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
37 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-7"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 37 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-7"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
38 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 38 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
39 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·7</xccdf-1.2:title> | 39 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·7</xccdf-1.2:title> |
40 | ······<xccdf-1.2:description> | 40 | ······<xccdf-1.2:description> |
41 | ········This·guide·presents·a·catalog·of·security-relevant | 41 | ········This·guide·presents·a·catalog·of·security-relevant |
42 | configuration·settings·for·Oracle·Linux·7.·It·is·a·rendering·of | 42 | configuration·settings·for·Oracle·Linux·7.·It·is·a·rendering·of |
43 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 43 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 237865, 15 lines modified | Offset 237865, 15 lines modified | ||
237865 | ··············<xccdf-1.2:check-content-ref·href="ssg-ol7-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/> | 237865 | ··············<xccdf-1.2:check-content-ref·href="ssg-ol7-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/> |
237866 | ············</xccdf-1.2:check> | 237866 | ············</xccdf-1.2:check> |
237867 | ··········</xccdf-1.2:Rule> | 237867 | ··········</xccdf-1.2:Rule> |
237868 | ········</xccdf-1.2:Group> | 237868 | ········</xccdf-1.2:Group> |
237869 | ······</xccdf-1.2:Group> | 237869 | ······</xccdf-1.2:Group> |
237870 | ····</xccdf-1.2:Benchmark> | 237870 | ····</xccdf-1.2:Benchmark> |
237871 | ··</ds:component> | 237871 | ··</ds:component> |
237872 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-oval.xml"·timestamp="2025-0 | 237872 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-oval.xml"·timestamp="2025-03-01T22:08:00"> |
237873 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 237873 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
237874 | ······<oval-def:generator> | 237874 | ······<oval-def:generator> |
237875 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 237875 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
237876 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 237876 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
237877 | ········<oval:schema_version>5.11</oval:schema_version> | 237877 | ········<oval:schema_version>5.11</oval:schema_version> |
237878 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 237878 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
237879 | ······</oval-def:generator> | 237879 | ······</oval-def:generator> |
Offset 286201, 10951 lines modified | Offset 286201, 10951 lines modified | ||
286201 | ············</oval-def:arithmetic> | 286201 | ············</oval-def:arithmetic> |
286202 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 286202 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
286203 | ··········</oval-def:arithmetic> | 286203 | ··········</oval-def:arithmetic> |
286204 | ········</oval-def:local_variable> | 286204 | ········</oval-def:local_variable> |
286205 | ······</oval-def:variables> | 286205 | ······</oval-def:variables> |
286206 | ····</oval-def:oval_definitions> | 286206 | ····</oval-def:oval_definitions> |
286207 | ··</ds:component> | 286207 | ··</ds:component> |
286208 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-ocil.xml"·timestamp="2025-0 | 286208 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
286209 | ····<ocil:ocil> | 286209 | ····<ocil:ocil> |
286210 | ······<ocil:generator> | 286210 | ······<ocil:generator> |
286211 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 286211 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
286212 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 286212 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
286213 | ········<ocil:schema_version>2.0</ocil:schema_version> | 286213 | ········<ocil:schema_version>2.0</ocil:schema_version> |
286214 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 286214 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
286215 | ······</ocil:generator> | 286215 | ······</ocil:generator> |
286216 | ······<ocil:questionnaires> | 286216 | ······<ocil:questionnaires> |
286217 | ········<ocil:questionnaire·id="ocil:ssg- | 286217 | ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_idle_activation_locked_ocil:questionnaire:1"> |
286218 | ··········<ocil:title>Ensure·Users·Cannot·Change·GNOME3·Screensaver·Idle·Activation</ocil:title> | ||
286218 | ··········<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fsetxattr</ocil:title> | ||
286219 | ··········<ocil:actions> | ||
286220 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fsetxattr_action:testaction:1</ocil:test_action_ref> | ||
286221 | ··········</ocil:actions> | ||
286222 | ········</ocil:questionnaire> | ||
286223 | ········<ocil:questionnaire·id="ocil:ssg-package_policycoreutils_installed_ocil:questionnaire:1"> | ||
286224 | ··········<ocil:title>Install·policycoreutils·Package</ocil:title> | ||
286225 | ··········<ocil:actions> | 286219 | ··········<ocil:actions> |
286226 | ············<ocil:test_action_ref>ocil:ssg- | 286220 | ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_idle_activation_locked_action:testaction:1</ocil:test_action_ref> |
286227 | ··········</ocil:actions> | 286221 | ··········</ocil:actions> |
286228 | ········</ocil:questionnaire> | 286222 | ········</ocil:questionnaire> |
286229 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1"> | ||
286230 | ········ | 286223 | ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1"> |
286224 | ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Different·Categories</ocil:title> | ||
286231 | ··········<ocil:actions> | 286225 | ··········<ocil:actions> |
286232 | ············<ocil:test_action_ref>ocil:ssg- | 286226 | ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minclass_action:testaction:1</ocil:test_action_ref> |
286233 | ··········</ocil:actions> | 286227 | ··········</ocil:actions> |
286234 | ········</ocil:questionnaire> | 286228 | ········</ocil:questionnaire> |
286235 | ········<ocil:questionnaire·id="ocil:ssg-rpm_verify_ownership_ocil:questionnaire:1"> | ||
286236 | ········ | 286229 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_lsetxattr_ocil:questionnaire:1"> |
286230 | ··········<ocil:title>Record·Successful·Permission·Changes·to·Files·-·lsetxattr</ocil:title> | ||
286237 | ··········<ocil:actions> | 286231 | ··········<ocil:actions> |
286238 | ············<ocil:test_action_ref>ocil:ssg-r | 286232 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_lsetxattr_action:testaction:1</ocil:test_action_ref> |
286239 | ··········</ocil:actions> | 286233 | ··········</ocil:actions> |
286240 | ········</ocil:questionnaire> | 286234 | ········</ocil:questionnaire> |
286241 | ········<ocil:questionnaire·id="ocil:ssg- | 286235 | ········<ocil:questionnaire·id="ocil:ssg-mount_option_boot_nodev_ocil:questionnaire:1"> |
286242 | ··········<ocil:title> | 286236 | ··········<ocil:title>Add·nodev·Option·to·/boot</ocil:title> |
286243 | ··········<ocil:actions> | 286237 | ··········<ocil:actions> |
286244 | ············<ocil:test_action_ref>ocil:ssg- | 286238 | ············<ocil:test_action_ref>ocil:ssg-mount_option_boot_nodev_action:testaction:1</ocil:test_action_ref> |
286245 | ··········</ocil:actions> | 286239 | ··········</ocil:actions> |
286246 | ········</ocil:questionnaire> | 286240 | ········</ocil:questionnaire> |
286247 | ········<ocil:questionnaire·id="ocil:ssg- | 286241 | ········<ocil:questionnaire·id="ocil:ssg-grub2_vsyscall_argument_ocil:questionnaire:1"> |
286248 | ··········<ocil:title> | 286242 | ··········<ocil:title>Disable·vsyscalls</ocil:title> |
286249 | ··········<ocil:actions> | 286243 | ··········<ocil:actions> |
286250 | ············<ocil:test_action_ref>ocil:ssg- | 286244 | ············<ocil:test_action_ref>ocil:ssg-grub2_vsyscall_argument_action:testaction:1</ocil:test_action_ref> |
286251 | ··········</ocil:actions> | 286245 | ··········</ocil:actions> |
286252 | ········</ocil:questionnaire> | 286246 | ········</ocil:questionnaire> |
286253 | ········<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1"> | ||
286254 | ········ | 286247 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_ocil:questionnaire:1"> |
286248 | ··········<ocil:title>Disable·Kernel·Parameter·for·IPv6·Forwarding</ocil:title> | ||
286255 | ··········<ocil:actions> | 286249 | ··········<ocil:actions> |
286256 | ············<ocil:test_action_ref>ocil:ssg- | 286250 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_action:testaction:1</ocil:test_action_ref> |
286257 | ··········</ocil:actions> | 286251 | ··········</ocil:actions> |
286258 | ········</ocil:questionnaire> | 286252 | ········</ocil:questionnaire> |
286259 | ········<ocil:questionnaire·id="ocil:ssg- | 286253 | ········<ocil:questionnaire·id="ocil:ssg-package_uuidd_installed_ocil:questionnaire:1"> |
286260 | ··········<ocil:title> | 286254 | ··········<ocil:title>Package·uuidd·Installed</ocil:title> |
286261 | ··········<ocil:actions> | 286255 | ··········<ocil:actions> |
286262 | ············<ocil:test_action_ref>ocil:ssg- | 286256 | ············<ocil:test_action_ref>ocil:ssg-package_uuidd_installed_action:testaction:1</ocil:test_action_ref> |
286263 | ··········</ocil:actions> | 286257 | ··········</ocil:actions> |
286264 | ········</ocil:questionnaire> | 286258 | ········</ocil:questionnaire> |
286265 | ········<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1"> | ||
286266 | ········ | 286259 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_open_ocil:questionnaire:1"> |
286260 | ··········<ocil:title>Record·Successful·Access·Attempts·to·Files·-·open</ocil:title> | ||
286267 | ··········<ocil:actions> | 286261 | ··········<ocil:actions> |
286268 | ············<ocil:test_action_ref>ocil:ssg- | 286262 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_open_action:testaction:1</ocil:test_action_ref> |
286269 | ··········</ocil:actions> | 286263 | ··········</ocil:actions> |
286270 | ········</ocil:questionnaire> | 286264 | ········</ocil:questionnaire> |
286271 | ········<ocil:questionnaire·id="ocil:ssg- | 286265 | ········<ocil:questionnaire·id="ocil:ssg-grub2_enable_fips_mode_ocil:questionnaire:1"> |
286272 | ··········<ocil:title>En | 286266 | ··········<ocil:title>Enable·FIPS·Mode·in·GRUB2</ocil:title> |
286273 | ··········<ocil:actions> | 286267 | ··········<ocil:actions> |
286274 | ············<ocil:test_action_ref>ocil:ssg- | 286268 | ············<ocil:test_action_ref>ocil:ssg-grub2_enable_fips_mode_action:testaction:1</ocil:test_action_ref> |
286275 | ··········</ocil:actions> | 286269 | ··········</ocil:actions> |
286276 | ········</ocil:questionnaire> | 286270 | ········</ocil:questionnaire> |
286277 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner | 286271 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_sshd_config_ocil:questionnaire:1"> |
286278 | ··········<ocil:title>Verify·Group· | 286272 | ··········<ocil:title>Verify·Group·Who·Owns·SSH·Server·config·file</ocil:title> |
286279 | ··········<ocil:actions> | 286273 | ··········<ocil:actions> |
286280 | ············<ocil:test_action_ref>ocil:ssg-file_groupowner | 286274 | ············<ocil:test_action_ref>ocil:ssg-file_groupowner_sshd_config_action:testaction:1</ocil:test_action_ref> |
286281 | ··········</ocil:actions> | 286275 | ··········</ocil:actions> |
286282 | ········</ocil:questionnaire> | 286276 | ········</ocil:questionnaire> |
Max diff block lines reached; 2282183/2294156 bytes (99.48%) of diff not shown. |
Offset 3, 10942 lines modified | Offset 3, 10942 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg- | 10 | ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_idle_activation_locked_ocil:questionnaire:1"> |
11 | ······<ocil:title>Ensure·Users·Cannot·Change·GNOME3·Screensaver·Idle·Activation</ocil:title> | ||
11 | ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fsetxattr</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fsetxattr_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-package_policycoreutils_installed_ocil:questionnaire:1"> | ||
17 | ······<ocil:title>Install·policycoreutils·Package</ocil:title> | ||
18 | ······<ocil:actions> | 12 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_idle_activation_locked_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 14 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1"> | ||
23 | ···· | 16 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1"> |
17 | ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Different·Categories</ocil:title> | ||
24 | ······<ocil:actions> | 18 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minclass_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 20 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_ownership_ocil:questionnaire:1"> | ||
29 | ···· | 22 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_lsetxattr_ocil:questionnaire:1"> |
23 | ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·lsetxattr</ocil:title> | ||
30 | ······<ocil:actions> | 24 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg-r | 25 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_lsetxattr_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 26 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg- | 28 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_nodev_ocil:questionnaire:1"> |
35 | ······<ocil:title> | 29 | ······<ocil:title>Add·nodev·Option·to·/boot</ocil:title> |
36 | ······<ocil:actions> | 30 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_nodev_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 32 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-grub2_vsyscall_argument_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 35 | ······<ocil:title>Disable·vsyscalls</ocil:title> |
42 | ······<ocil:actions> | 36 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-grub2_vsyscall_argument_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 38 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1"> | ||
47 | ···· | 40 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_ocil:questionnaire:1"> |
41 | ······<ocil:title>Disable·Kernel·Parameter·for·IPv6·Forwarding</ocil:title> | ||
48 | ······<ocil:actions> | 42 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 44 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 46 | ····<ocil:questionnaire·id="ocil:ssg-package_uuidd_installed_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 47 | ······<ocil:title>Package·uuidd·Installed</ocil:title> |
54 | ······<ocil:actions> | 48 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-package_uuidd_installed_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 50 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1"> | ||
59 | ···· | 52 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_open_ocil:questionnaire:1"> |
53 | ······<ocil:title>Record·Successful·Access·Attempts·to·Files·-·open</ocil:title> | ||
60 | ······<ocil:actions> | 54 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_open_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 56 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_fips_mode_ocil:questionnaire:1"> |
65 | ······<ocil:title>En | 59 | ······<ocil:title>Enable·FIPS·Mode·in·GRUB2</ocil:title> |
66 | ······<ocil:actions> | 60 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-grub2_enable_fips_mode_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 62 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner | 64 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_sshd_config_ocil:questionnaire:1"> |
71 | ······<ocil:title>Verify·Group· | 65 | ······<ocil:title>Verify·Group·Who·Owns·SSH·Server·config·file</ocil:title> |
72 | ······<ocil:actions> | 66 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner | 67 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_sshd_config_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 68 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-sudo_add_ignore_dot_ocil:questionnaire:1"> |
77 | ······<ocil:title> | 71 | ······<ocil:title>Ensure·sudo·Ignores·Commands·In·Current·Dir·-·sudo·ignore_dot</ocil:title> |
78 | ······<ocil:actions> | 72 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-sudo_add_ignore_dot_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 74 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-aide_verify_ext_attributes_ocil:questionnaire:1"> | ||
83 | ···· | 76 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1"> |
77 | ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title> | ||
84 | ······<ocil:actions> | 78 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg-ai | 79 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 80 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg- | 82 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_efi_user_cfg_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 83 | ······<ocil:title>Verify·/boot/efi/EFI/redhat/user.cfg·Group·Ownership</ocil:title> |
90 | ······<ocil:actions> | 84 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_efi_user_cfg_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 86 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg- | 88 | ····<ocil:questionnaire·id="ocil:ssg-security_patches_up_to_date_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 89 | ······<ocil:title>Ensure·Software·Patches·Installed</ocil:title> |
96 | ······<ocil:actions> | 90 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-security_patches_up_to_date_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 92 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-d | 94 | ····<ocil:questionnaire·id="ocil:ssg-ldap_client_start_tls_ocil:questionnaire:1"> |
101 | ······<ocil:title> | 95 | ······<ocil:title>Configure·LDAP·Client·to·Use·TLS·For·All·Transactions</ocil:title> |
102 | ······<ocil:actions> | 96 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg-d | 97 | ········<ocil:test_action_ref>ocil:ssg-ldap_client_start_tls_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 98 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_ | 100 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1"> |
107 | ······<ocil:title>Verify· | 101 | ······<ocil:title>Verify·User·Who·Owns·Backup·passwd·File</ocil:title> |
108 | ······<ocil:actions> | 102 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg-file_owner_ | 103 | ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 104 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg- | 106 | ····<ocil:questionnaire·id="ocil:ssg-dconf_db_up_to_date_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 107 | ······<ocil:title>Make·sure·that·the·dconf·databases·are·up-to-date·with·regards·to·respective·keyfiles</ocil:title> |
114 | ······<ocil:actions> | 108 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-dconf_db_up_to_date_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 110 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1"> | ||
119 | ···· | 112 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_lchown_ocil:questionnaire:1"> |
113 | ······<ocil:title>Record·Unsuccessful·Ownership·Changes·to·Files·-·lchown</ocil:title> | ||
120 | ······<ocil:actions> | 114 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_lchown_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 116 | ······</ocil:actions> |
Max diff block lines reached; 2184521/2196832 bytes (99.44%) of diff not shown. |
Offset 21, 23 lines modified | Offset 21, 23 lines modified | ||
21 | ····<ds:checks> | 21 | ····<ds:checks> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-oval.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-oval.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-ocil.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-ocil.xml"/> |
24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-cpe-oval.xml"/> | 24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-cpe-oval.xml"/> |
25 | ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol8.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol8.xml.bz2"/> | 25 | ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol8.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol8.xml.bz2"/> |
26 | ····</ds:checks> | 26 | ····</ds:checks> |
27 | ··</ds:data-stream> | 27 | ··</ds:data-stream> |
28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-cpe-dictionary.xml"·timestamp="2025-0 | 28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
30 | ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:8"> | 30 | ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:8"> |
31 | ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·8</cpe-dict:title> | 31 | ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·8</cpe-dict:title> |
32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml">oval:ssg-installed_OS_is_ol8:def:1</cpe-dict:check> | 32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml">oval:ssg-installed_OS_is_ol8:def:1</cpe-dict:check> |
33 | ······</cpe-dict:cpe-item> | 33 | ······</cpe-dict:cpe-item> |
34 | ····</cpe-dict:cpe-list> | 34 | ····</cpe-dict:cpe-list> |
35 | ··</ds:component> | 35 | ··</ds:component> |
36 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-xccdf.xml"·timestamp="2025-0 | 36 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
37 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 37 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
38 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 38 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
39 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·8</xccdf-1.2:title> | 39 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·8</xccdf-1.2:title> |
40 | ······<xccdf-1.2:description> | 40 | ······<xccdf-1.2:description> |
41 | ········This·guide·presents·a·catalog·of·security-relevant | 41 | ········This·guide·presents·a·catalog·of·security-relevant |
42 | configuration·settings·for·Oracle·Linux·8.·It·is·a·rendering·of | 42 | configuration·settings·for·Oracle·Linux·8.·It·is·a·rendering·of |
43 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 43 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 386, 25 lines modified | Offset 386, 25 lines modified | ||
386 | ··········</cpe-lang:logical-test> | 386 | ··········</cpe-lang:logical-test> |
387 | ········</cpe-lang:platform> | 387 | ········</cpe-lang:platform> |
388 | ········<cpe-lang:platform·id="package_bash"> | 388 | ········<cpe-lang:platform·id="package_bash"> |
389 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 389 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
390 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> | 390 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> |
391 | ··········</cpe-lang:logical-test> | 391 | ··········</cpe-lang:logical-test> |
392 | ········</cpe-lang:platform> | 392 | ········</cpe-lang:platform> |
393 | ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> | ||
394 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | ||
395 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> | ||
396 | ··········</cpe-lang:logical-test> | ||
397 | ········</cpe-lang:platform> | ||
398 | ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0"> | 393 | ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0"> |
399 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 394 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
400 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/> | 395 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/> |
401 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> | 396 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> |
402 | ··········</cpe-lang:logical-test> | 397 | ··········</cpe-lang:logical-test> |
403 | ········</cpe-lang:platform> | 398 | ········</cpe-lang:platform> |
399 | ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> | ||
400 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | ||
401 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> | ||
402 | ··········</cpe-lang:logical-test> | ||
403 | ········</cpe-lang:platform> | ||
404 | ········<cpe-lang:platform·id="not_s390x_arch"> | 404 | ········<cpe-lang:platform·id="not_s390x_arch"> |
405 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 405 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
406 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> | 406 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> |
407 | ··········</cpe-lang:logical-test> | 407 | ··········</cpe-lang:logical-test> |
408 | ········</cpe-lang:platform> | 408 | ········</cpe-lang:platform> |
409 | ········<cpe-lang:platform·id="package_tmux"> | 409 | ········<cpe-lang:platform·id="package_tmux"> |
410 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 410 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
Offset 264643, 15 lines modified | Offset 264643, 15 lines modified | ||
264643 | ··············<xccdf-1.2:check-content-ref·href="ssg-ol8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/> | 264643 | ··············<xccdf-1.2:check-content-ref·href="ssg-ol8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/> |
264644 | ············</xccdf-1.2:check> | 264644 | ············</xccdf-1.2:check> |
264645 | ··········</xccdf-1.2:Rule> | 264645 | ··········</xccdf-1.2:Rule> |
264646 | ········</xccdf-1.2:Group> | 264646 | ········</xccdf-1.2:Group> |
264647 | ······</xccdf-1.2:Group> | 264647 | ······</xccdf-1.2:Group> |
264648 | ····</xccdf-1.2:Benchmark> | 264648 | ····</xccdf-1.2:Benchmark> |
264649 | ··</ds:component> | 264649 | ··</ds:component> |
264650 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-oval.xml"·timestamp="2025-0 | 264650 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-oval.xml"·timestamp="2025-03-01T22:08:00"> |
264651 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 264651 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
264652 | ······<oval-def:generator> | 264652 | ······<oval-def:generator> |
264653 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 264653 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
264654 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 264654 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
264655 | ········<oval:schema_version>5.11</oval:schema_version> | 264655 | ········<oval:schema_version>5.11</oval:schema_version> |
264656 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 264656 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
264657 | ······</oval-def:generator> | 264657 | ······</oval-def:generator> |
Offset 321125, 10521 lines modified | Offset 321125, 10521 lines modified | ||
321125 | ············</oval-def:arithmetic> | 321125 | ············</oval-def:arithmetic> |
321126 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 321126 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
321127 | ··········</oval-def:arithmetic> | 321127 | ··········</oval-def:arithmetic> |
321128 | ········</oval-def:local_variable> | 321128 | ········</oval-def:local_variable> |
321129 | ······</oval-def:variables> | 321129 | ······</oval-def:variables> |
321130 | ····</oval-def:oval_definitions> | 321130 | ····</oval-def:oval_definitions> |
321131 | ··</ds:component> | 321131 | ··</ds:component> |
321132 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-ocil.xml"·timestamp="2025-0 | 321132 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
321133 | ····<ocil:ocil> | 321133 | ····<ocil:ocil> |
321134 | ······<ocil:generator> | 321134 | ······<ocil:generator> |
321135 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 321135 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
321136 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 321136 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
321137 | ········<ocil:schema_version>2.0</ocil:schema_version> | 321137 | ········<ocil:schema_version>2.0</ocil:schema_version> |
321138 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 321138 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
321139 | ······</ocil:generator> | 321139 | ······</ocil:generator> |
321140 | ······<ocil:questionnaires> | 321140 | ······<ocil:questionnaires> |
321141 | ········<ocil:questionnaire·id="ocil:ssg- | 321141 | ········<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1"> |
321142 | ··········<ocil:title> | 321142 | ··········<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title> |
321143 | ··········<ocil:actions> | 321143 | ··········<ocil:actions> |
321144 | ············<ocil:test_action_ref>ocil:ssg- | 321144 | ············<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref> |
321145 | ··········</ocil:actions> | 321145 | ··········</ocil:actions> |
321146 | ········</ocil:questionnaire> | 321146 | ········</ocil:questionnaire> |
321147 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order_ocil:questionnaire:1"> | ||
321148 | ········ | 321147 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1"> |
321148 | ··········<ocil:title>Kernel·panic·oops</ocil:title> | ||
321149 | ··········<ocil:actions> | 321149 | ··········<ocil:actions> |
321150 | ············<ocil:test_action_ref>ocil:ssg- | 321150 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_panic_on_oops_action:testaction:1</ocil:test_action_ref> |
321151 | ··········</ocil:actions> | 321151 | ··········</ocil:actions> |
321152 | ········</ocil:questionnaire> | 321152 | ········</ocil:questionnaire> |
321153 | ········<ocil:questionnaire·id="ocil:ssg- | 321153 | ········<ocil:questionnaire·id="ocil:ssg-dir_system_commands_root_owned_ocil:questionnaire:1"> |
321154 | ··········<ocil:title> | 321154 | ··········<ocil:title>Verify·that·system·commands·directories·have·root·ownership</ocil:title> |
321155 | ··········<ocil:actions> | 321155 | ··········<ocil:actions> |
321156 | ············<ocil:test_action_ref>ocil:ssg- | 321156 | ············<ocil:test_action_ref>ocil:ssg-dir_system_commands_root_owned_action:testaction:1</ocil:test_action_ref> |
321157 | ··········</ocil:actions> | 321157 | ··········</ocil:actions> |
321158 | ········</ocil:questionnaire> | 321158 | ········</ocil:questionnaire> |
321159 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 321159 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_postqueue_ocil:questionnaire:1"> |
321160 | ··········<ocil:title> | 321160 | ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·postqueue</ocil:title> |
321161 | ··········<ocil:actions> | 321161 | ··········<ocil:actions> |
321162 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_ | 321162 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_postqueue_action:testaction:1</ocil:test_action_ref> |
321163 | ··········</ocil:actions> | 321163 | ··········</ocil:actions> |
321164 | ········</ocil:questionnaire> | 321164 | ········</ocil:questionnaire> |
321165 | ········<ocil:questionnaire·id="ocil:ssg- | 321165 | ········<ocil:questionnaire·id="ocil:ssg-sebool_ssh_chroot_rw_homedirs_ocil:questionnaire:1"> |
321166 | ··········<ocil:title> | 321166 | ··········<ocil:title>Disable·the·ssh_chroot_rw_homedirs·SELinux·Boolean</ocil:title> |
321167 | ··········<ocil:actions> | 321167 | ··········<ocil:actions> |
321168 | ············<ocil:test_action_ref>ocil:ssg- | 321168 | ············<ocil:test_action_ref>ocil:ssg-sebool_ssh_chroot_rw_homedirs_action:testaction:1</ocil:test_action_ref> |
321169 | ··········</ocil:actions> | 321169 | ··········</ocil:actions> |
321170 | ········</ocil:questionnaire> | 321170 | ········</ocil:questionnaire> |
321171 | ········<ocil:questionnaire·id="ocil:ssg-r | 321171 | ········<ocil:questionnaire·id="ocil:ssg-chronyd_or_ntpd_set_maxpoll_ocil:questionnaire:1"> |
321172 | ··········<ocil:title> | 321172 | ··········<ocil:title>Configure·Time·Service·Maxpoll·Interval</ocil:title> |
321173 | ··········<ocil:actions> | 321173 | ··········<ocil:actions> |
321174 | ············<ocil:test_action_ref>ocil:ssg-r | 321174 | ············<ocil:test_action_ref>ocil:ssg-chronyd_or_ntpd_set_maxpoll_action:testaction:1</ocil:test_action_ref> |
321175 | ··········</ocil:actions> | 321175 | ··········</ocil:actions> |
321176 | ········</ocil:questionnaire> | 321176 | ········</ocil:questionnaire> |
321177 | ········<ocil:questionnaire·id="ocil:ssg- | 321177 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_no_sanity_ocil:questionnaire:1"> |
321178 | ··········<ocil:title>Enable· | 321178 | ··········<ocil:title>Enable·poison·without·sanity·check</ocil:title> |
321179 | ··········<ocil:actions> | 321179 | ··········<ocil:actions> |
Max diff block lines reached; 2703592/2715051 bytes (99.58%) of diff not shown. |
Offset 3, 10512 lines modified | Offset 3, 10512 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_ocil:questionnaire:1"> | ||
11 | ···· | 10 | ····<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1"> |
11 | ······<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title> | ||
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order_ocil:questionnaire:1"> | ||
17 | ···· | 16 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1"> |
17 | ······<ocil:title>Kernel·panic·oops</ocil:title> | ||
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_on_oops_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1"> | ||
23 | ···· | 22 | ····<ocil:questionnaire·id="ocil:ssg-dir_system_commands_root_owned_ocil:questionnaire:1"> |
23 | ······<ocil:title>Verify·that·system·commands·directories·have·root·ownership</ocil:title> | ||
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-dir_system_commands_root_owned_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 28 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_postqueue_ocil:questionnaire:1"> |
29 | ······<ocil:title> | 29 | ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·postqueue</ocil:title> |
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_ | 31 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_postqueue_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-sebool_ssh_chroot_rw_homedirs_ocil:questionnaire:1"> |
35 | ······<ocil:title> | 35 | ······<ocil:title>Disable·the·ssh_chroot_rw_homedirs·SELinux·Boolean</ocil:title> |
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-sebool_ssh_chroot_rw_homedirs_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-r | 40 | ····<ocil:questionnaire·id="ocil:ssg-chronyd_or_ntpd_set_maxpoll_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 41 | ······<ocil:title>Configure·Time·Service·Maxpoll·Interval</ocil:title> |
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg-r | 43 | ········<ocil:test_action_ref>ocil:ssg-chronyd_or_ntpd_set_maxpoll_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg- | 46 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_no_sanity_ocil:questionnaire:1"> |
47 | ······<ocil:title>Enable· | 47 | ······<ocil:title>Enable·poison·without·sanity·check</ocil:title> |
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_no_sanity_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 52 | ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_dir_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 53 | ······<ocil:title>Account·Lockouts·Must·Persist</ocil:title> |
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_sudoers_ocil:questionnaire:1"> | ||
59 | ···· | 58 | ····<ocil:questionnaire·id="ocil:ssg-timer_dnf-automatic_enabled_ocil:questionnaire:1"> |
59 | ······<ocil:title>Enable·dnf-automatic·Timer</ocil:title> | ||
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-timer_dnf-automatic_enabled_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_creat_ocil:questionnaire:1"> | ||
65 | ···· | 64 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1"> |
65 | ······<ocil:title>Disable·kernel·debugfs</ocil:title> | ||
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-service_fapolicyd_enabled_ocil:questionnaire:1"> |
71 | ······<ocil:title>Enable· | 71 | ······<ocil:title>Enable·the·File·Access·Policy·Service</ocil:title> |
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-service_fapolicyd_enabled_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg- | 76 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1"> |
77 | ······<ocil:title>Disable· | 77 | ······<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title> |
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_krb_sec_remote_filesystems_ocil:questionnaire:1"> | ||
83 | ···· | 82 | ····<ocil:questionnaire·id="ocil:ssg-sudo_add_passwd_timeout_ocil:questionnaire:1"> |
83 | ······<ocil:title>Ensure·sudo·passwd_timeout·is·appropriate·-·sudo·passwd_timeout</ocil:title> | ||
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-sudo_add_passwd_timeout_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-ss | 88 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_creat_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 89 | ······<ocil:title>Record·Successful·Access·Attempts·to·Files·-·creat</ocil:title> |
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg-ss | 91 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_creat_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1"> | ||
95 | ····· | 94 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ssh_keysign_ocil:questionnaire:1"> |
95 | ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·ssh-keysign</ocil:title> | ||
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg-p | 97 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_ssh_keysign_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1"> |
101 | ······<ocil:title> | 101 | ······<ocil:title>Verify·Owner·on·crontab</ocil:title> |
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dictcheck_ocil:questionnaire:1"> | ||
107 | ···· | 106 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1"> |
107 | ······<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title> | ||
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg- | 112 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_nosuid_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 113 | ······<ocil:title>Add·nosuid·Option·to·/boot</ocil:title> |
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_nosuid_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_usr_share_ocil:questionnaire:1"> | ||
119 | ···· | 118 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_perf_event_paranoid_ocil:questionnaire:1"> |
119 | ······<ocil:title>Disallow·kernel·profiling·by·unprivileged·users</ocil:title> | ||
120 | ······<ocil:actions> | 120 | ······<ocil:actions> |
Max diff block lines reached; 2588513/2600987 bytes (99.52%) of diff not shown. |
Offset 351, 25 lines modified | Offset 351, 25 lines modified | ||
351 | ······</cpe-lang:logical-test> | 351 | ······</cpe-lang:logical-test> |
352 | ····</cpe-lang:platform> | 352 | ····</cpe-lang:platform> |
353 | ····<cpe-lang:platform·id="package_bash"> | 353 | ····<cpe-lang:platform·id="package_bash"> |
354 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 354 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
355 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> | 355 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> |
356 | ······</cpe-lang:logical-test> | 356 | ······</cpe-lang:logical-test> |
357 | ····</cpe-lang:platform> | 357 | ····</cpe-lang:platform> |
358 | ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> | ||
359 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | ||
360 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> | ||
361 | ······</cpe-lang:logical-test> | ||
362 | ····</cpe-lang:platform> | ||
363 | ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0"> | 358 | ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0"> |
364 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 359 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
365 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/> | 360 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/> |
366 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> | 361 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> |
367 | ······</cpe-lang:logical-test> | 362 | ······</cpe-lang:logical-test> |
368 | ····</cpe-lang:platform> | 363 | ····</cpe-lang:platform> |
364 | ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> | ||
365 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | ||
366 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> | ||
367 | ······</cpe-lang:logical-test> | ||
368 | ····</cpe-lang:platform> | ||
369 | ····<cpe-lang:platform·id="not_s390x_arch"> | 369 | ····<cpe-lang:platform·id="not_s390x_arch"> |
370 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 370 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
371 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> | 371 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> |
372 | ······</cpe-lang:logical-test> | 372 | ······</cpe-lang:logical-test> |
373 | ····</cpe-lang:platform> | 373 | ····</cpe-lang:platform> |
374 | ····<cpe-lang:platform·id="package_tmux"> | 374 | ····<cpe-lang:platform·id="package_tmux"> |
375 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 375 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
Offset 21, 23 lines modified | Offset 21, 23 lines modified | ||
21 | ····<ds:checks> | 21 | ····<ds:checks> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-oval.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-oval.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-ocil.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-ocil.xml"/> |
24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-cpe-oval.xml"/> | 24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-cpe-oval.xml"/> |
25 | ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol9.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol9.xml.bz2"/> | 25 | ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol9.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol9.xml.bz2"/> |
26 | ····</ds:checks> | 26 | ····</ds:checks> |
27 | ··</ds:data-stream> | 27 | ··</ds:data-stream> |
28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-cpe-dictionary.xml"·timestamp="2025-0 | 28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
30 | ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:9"> | 30 | ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:9"> |
31 | ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·9</cpe-dict:title> | 31 | ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·9</cpe-dict:title> |
32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml">oval:ssg-installed_OS_is_ol9:def:1</cpe-dict:check> | 32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml">oval:ssg-installed_OS_is_ol9:def:1</cpe-dict:check> |
33 | ······</cpe-dict:cpe-item> | 33 | ······</cpe-dict:cpe-item> |
34 | ····</cpe-dict:cpe-list> | 34 | ····</cpe-dict:cpe-list> |
35 | ··</ds:component> | 35 | ··</ds:component> |
36 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-xccdf.xml"·timestamp="2025-0 | 36 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
37 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 37 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
38 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 38 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
39 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·9</xccdf-1.2:title> | 39 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·9</xccdf-1.2:title> |
40 | ······<xccdf-1.2:description> | 40 | ······<xccdf-1.2:description> |
41 | ········This·guide·presents·a·catalog·of·security-relevant | 41 | ········This·guide·presents·a·catalog·of·security-relevant |
42 | configuration·settings·for·Oracle·Linux·9.·It·is·a·rendering·of | 42 | configuration·settings·for·Oracle·Linux·9.·It·is·a·rendering·of |
43 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 43 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 204458, 15 lines modified | Offset 204458, 15 lines modified | ||
204458 | ··············<xccdf-1.2:check-content-ref·href="ssg-ol9-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ocil:questionnaire:1"/> | 204458 | ··············<xccdf-1.2:check-content-ref·href="ssg-ol9-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ocil:questionnaire:1"/> |
204459 | ············</xccdf-1.2:check> | 204459 | ············</xccdf-1.2:check> |
204460 | ··········</xccdf-1.2:Rule> | 204460 | ··········</xccdf-1.2:Rule> |
204461 | ········</xccdf-1.2:Group> | 204461 | ········</xccdf-1.2:Group> |
204462 | ······</xccdf-1.2:Group> | 204462 | ······</xccdf-1.2:Group> |
204463 | ····</xccdf-1.2:Benchmark> | 204463 | ····</xccdf-1.2:Benchmark> |
204464 | ··</ds:component> | 204464 | ··</ds:component> |
204465 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-oval.xml"·timestamp="2025-0 | 204465 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-oval.xml"·timestamp="2025-03-01T22:08:00"> |
204466 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 204466 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
204467 | ······<oval-def:generator> | 204467 | ······<oval-def:generator> |
204468 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 204468 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
204469 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 204469 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
204470 | ········<oval:schema_version>5.11</oval:schema_version> | 204470 | ········<oval:schema_version>5.11</oval:schema_version> |
204471 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 204471 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
204472 | ······</oval-def:generator> | 204472 | ······</oval-def:generator> |
Offset 250354, 7517 lines modified | Offset 250354, 7517 lines modified | ||
250354 | ············</oval-def:arithmetic> | 250354 | ············</oval-def:arithmetic> |
250355 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 250355 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
250356 | ··········</oval-def:arithmetic> | 250356 | ··········</oval-def:arithmetic> |
250357 | ········</oval-def:local_variable> | 250357 | ········</oval-def:local_variable> |
250358 | ······</oval-def:variables> | 250358 | ······</oval-def:variables> |
250359 | ····</oval-def:oval_definitions> | 250359 | ····</oval-def:oval_definitions> |
250360 | ··</ds:component> | 250360 | ··</ds:component> |
250361 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-ocil.xml"·timestamp="2025-0 | 250361 | ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
250362 | ····<ocil:ocil> | 250362 | ····<ocil:ocil> |
250363 | ······<ocil:generator> | 250363 | ······<ocil:generator> |
250364 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 250364 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
250365 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 250365 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
250366 | ········<ocil:schema_version>2.0</ocil:schema_version> | 250366 | ········<ocil:schema_version>2.0</ocil:schema_version> |
250367 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 250367 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
250368 | ······</ocil:generator> | 250368 | ······</ocil:generator> |
250369 | ······<ocil:questionnaires> | 250369 | ······<ocil:questionnaires> |
250370 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_ | 250370 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_ocil:questionnaire:1"> |
250371 | ··········<ocil:title> | 250371 | ··········<ocil:title>Configure·Maximum·Number·of·Autoconfigured·Addresses·on·All·IPv6·Interfaces</ocil:title> |
250372 | ··········<ocil:actions> | 250372 | ··········<ocil:actions> |
250373 | ············<ocil:test_action_ref>ocil:ssg-sysctl_ | 250373 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_action:testaction:1</ocil:test_action_ref> |
250374 | ··········</ocil:actions> | 250374 | ··········</ocil:actions> |
250375 | ········</ocil:questionnaire> | 250375 | ········</ocil:questionnaire> |
250376 | ········<ocil:questionnaire·id="ocil:ssg- | 250376 | ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1"> |
250377 | ··········<ocil:title> | 250377 | ··········<ocil:title>Configure·auditd·space_left·on·Low·Disk·Space</ocil:title> |
250378 | ··········<ocil:actions> | 250378 | ··········<ocil:actions> |
250379 | ············<ocil:test_action_ref>ocil:ssg- | 250379 | ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action:testaction:1</ocil:test_action_ref> |
250380 | ··········</ocil:actions> | 250380 | ··········</ocil:actions> |
250381 | ········</ocil:questionnaire> | 250381 | ········</ocil:questionnaire> |
250382 | ········<ocil:questionnaire·id="ocil:ssg- | 250382 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1"> |
250383 | ··········<ocil:title>Re | 250383 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title> |
250384 | ··········<ocil:actions> | 250384 | ··········<ocil:actions> |
250385 | ············<ocil:test_action_ref>ocil:ssg- | 250385 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref> |
250386 | ··········</ocil:actions> | 250386 | ··········</ocil:actions> |
250387 | ········</ocil:questionnaire> | 250387 | ········</ocil:questionnaire> |
250388 | ········<ocil:questionnaire·id="ocil:ssg- | 250388 | ········<ocil:questionnaire·id="ocil:ssg-service_avahi-daemon_disabled_ocil:questionnaire:1"> |
250389 | ··········<ocil:title> | 250389 | ··········<ocil:title>Disable·Avahi·Server·Software</ocil:title> |
250390 | ··········<ocil:actions> | 250390 | ··········<ocil:actions> |
250391 | ············<ocil:test_action_ref>ocil:ssg- | 250391 | ············<ocil:test_action_ref>ocil:ssg-service_avahi-daemon_disabled_action:testaction:1</ocil:test_action_ref> |
250392 | ··········</ocil:actions> | 250392 | ··········</ocil:actions> |
250393 | ········</ocil:questionnaire> | 250393 | ········</ocil:questionnaire> |
250394 | ········<ocil:questionnaire·id="ocil:ssg- | 250394 | ········<ocil:questionnaire·id="ocil:ssg-configure_bashrc_exec_tmux_ocil:questionnaire:1"> |
250395 | ··········<ocil:title> | 250395 | ··········<ocil:title>Support·session·locking·with·tmux</ocil:title> |
250396 | ··········<ocil:actions> | 250396 | ··········<ocil:actions> |
250397 | ············<ocil:test_action_ref>ocil:ssg- | 250397 | ············<ocil:test_action_ref>ocil:ssg-configure_bashrc_exec_tmux_action:testaction:1</ocil:test_action_ref> |
250398 | ··········</ocil:actions> | 250398 | ··········</ocil:actions> |
250399 | ········</ocil:questionnaire> | 250399 | ········</ocil:questionnaire> |
250400 | ········<ocil:questionnaire·id="ocil:ssg- | 250400 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_ocil:questionnaire:1"> |
250401 | ··········<ocil:title> | 250401 | ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv6·Interfaces</ocil:title> |
250402 | ··········<ocil:actions> | 250402 | ··········<ocil:actions> |
250403 | ············<ocil:test_action_ref>ocil:ssg- | 250403 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref> |
250404 | ··········</ocil:actions> | 250404 | ··········</ocil:actions> |
250405 | ········</ocil:questionnaire> | 250405 | ········</ocil:questionnaire> |
250406 | ········<ocil:questionnaire·id="ocil:ssg-se | 250406 | ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1"> |
250407 | ··········<ocil:title> | 250407 | ··········<ocil:title>Enable·SSH·Warning·Banner</ocil:title> |
250408 | ··········<ocil:actions> | 250408 | ··········<ocil:actions> |
250409 | ············<ocil:test_action_ref>ocil:ssg-se | 250409 | ············<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref> |
250410 | ··········</ocil:actions> | 250410 | ··········</ocil:actions> |
250411 | ········</ocil:questionnaire> | 250411 | ········</ocil:questionnaire> |
250412 | ········<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_ipsecd_ocil:questionnaire:1"> | ||
250413 | ········ | 250412 | ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1"> |
250413 | ··········<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title> | ||
250414 | ··········<ocil:actions> | 250414 | ··········<ocil:actions> |
250415 | ············<ocil:test_action_ref>ocil:ssg-dire | 250415 | ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref> |
250416 | ··········</ocil:actions> | 250416 | ··········</ocil:actions> |
250417 | ········</ocil:questionnaire> | 250417 | ········</ocil:questionnaire> |
250418 | ········<ocil:questionnaire·id="ocil:ssg-a | 250418 | ········<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1"> |
250419 | ··········<ocil:title> | 250419 | ··········<ocil:title>Ensure·rsyslog·is·Installed</ocil:title> |
250420 | ··········<ocil:actions> | 250420 | ··········<ocil:actions> |
250421 | ············<ocil:test_action_ref>ocil:ssg-a | 250421 | ············<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref> |
250422 | ··········</ocil:actions> | 250422 | ··········</ocil:actions> |
250423 | ········</ocil:questionnaire> | 250423 | ········</ocil:questionnaire> |
250424 | ········<ocil:questionnaire·id="ocil:ssg- | 250424 | ········<ocil:questionnaire·id="ocil:ssg-logind_session_timeout_ocil:questionnaire:1"> |
250425 | ··········<ocil:title> | 250425 | ··········<ocil:title>Configure·Logind·to·terminate·idle·sessions·after·certain·time·of·inactivity</ocil:title> |
250426 | ··········<ocil:actions> | 250426 | ··········<ocil:actions> |
250427 | ············<ocil:test_action_ref>ocil:ssg- | 250427 | ············<ocil:test_action_ref>ocil:ssg-logind_session_timeout_action:testaction:1</ocil:test_action_ref> |
250428 | ··········</ocil:actions> | 250428 | ··········</ocil:actions> |
250429 | ········</ocil:questionnaire> | 250429 | ········</ocil:questionnaire> |
250430 | ········<ocil:questionnaire·id="ocil:ssg- | 250430 | ········<ocil:questionnaire·id="ocil:ssg-timer_logrotate_enabled_ocil:questionnaire:1"> |
250431 | ··········<ocil:title> | 250431 | ··········<ocil:title>Enable·logrotate·Timer</ocil:title> |
250432 | ··········<ocil:actions> | 250432 | ··········<ocil:actions> |
250433 | ············<ocil:test_action_ref>ocil:ssg- | 250433 | ············<ocil:test_action_ref>ocil:ssg-timer_logrotate_enabled_action:testaction:1</ocil:test_action_ref> |
250434 | ··········</ocil:actions> | 250434 | ··········</ocil:actions> |
250435 | ········</ocil:questionnaire> | 250435 | ········</ocil:questionnaire> |
250436 | ········<ocil:questionnaire·id="ocil:ssg-s | 250436 | ········<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1"> |
250437 | ··········<ocil:title> | 250437 | ··········<ocil:title>Verify·iptables·Enabled</ocil:title> |
250438 | ··········<ocil:actions> | 250438 | ··········<ocil:actions> |
250439 | ············<ocil:test_action_ref>ocil:ssg-s | 250439 | ············<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref> |
Max diff block lines reached; 2144553/2156974 bytes (99.42%) of diff not shown. |
Offset 3, 7508 lines modified | Offset 3, 7508 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_ | 10 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_ocil:questionnaire:1"> |
11 | ······<ocil:title> | 11 | ······<ocil:title>Configure·Maximum·Number·of·Autoconfigured·Addresses·on·All·IPv6·Interfaces</ocil:title> |
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg-sysctl_ | 13 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg- | 16 | ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1"> |
17 | ······<ocil:title> | 17 | ······<ocil:title>Configure·auditd·space_left·on·Low·Disk·Space</ocil:title> |
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1"> |
23 | ······<ocil:title>Re | 23 | ······<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title> |
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg- | 28 | ····<ocil:questionnaire·id="ocil:ssg-service_avahi-daemon_disabled_ocil:questionnaire:1"> |
29 | ······<ocil:title> | 29 | ······<ocil:title>Disable·Avahi·Server·Software</ocil:title> |
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-service_avahi-daemon_disabled_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-configure_bashrc_exec_tmux_ocil:questionnaire:1"> |
35 | ······<ocil:title> | 35 | ······<ocil:title>Support·session·locking·with·tmux</ocil:title> |
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-configure_bashrc_exec_tmux_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-enable_dracut_fips_module_ocil:questionnaire:1"> | ||
41 | ···· | 40 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_ocil:questionnaire:1"> |
41 | ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv6·Interfaces</ocil:title> | ||
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-se | 46 | ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1"> |
47 | ······<ocil:title> | 47 | ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title> |
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg-se | 49 | ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_ipsecd_ocil:questionnaire:1"> | ||
53 | ···· | 52 | ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1"> |
53 | ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title> | ||
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg-dire | 55 | ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-a | 58 | ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 59 | ······<ocil:title>Ensure·rsyslog·is·Installed</ocil:title> |
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg-a | 61 | ········<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-logind_session_timeout_ocil:questionnaire:1"> |
65 | ······<ocil:title> | 65 | ······<ocil:title>Configure·Logind·to·terminate·idle·sessions·after·certain·time·of·inactivity</ocil:title> |
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-logind_session_timeout_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-timer_logrotate_enabled_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 71 | ······<ocil:title>Enable·logrotate·Timer</ocil:title> |
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-timer_logrotate_enabled_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1"> | ||
77 | ···· | 76 | ····<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1"> |
77 | ······<ocil:title>Verify·iptables·Enabled</ocil:title> | ||
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg-s | 79 | ········<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg- | 82 | ····<ocil:questionnaire·id="ocil:ssg-sshd_x11_use_localhost_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 83 | ······<ocil:title>Prevent·remote·hosts·from·connecting·to·the·proxy·display</ocil:title> |
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-sshd_x11_use_localhost_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg- | 88 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 89 | ······<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title> |
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_unprivileged_bpf_disabled_accept_default_ocil:questionnaire:1"> | ||
95 | ···· | 94 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_mount_ocil:questionnaire:1"> |
95 | ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·mount</ocil:title> | ||
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_mount_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_binary_dirs_ocil:questionnaire:1"> |
101 | ······<ocil:title> | 101 | ······<ocil:title>Verify·that·System·Executables·Have·Root·Ownership</ocil:title> |
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-file_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg- | 106 | ····<ocil:questionnaire·id="ocil:ssg-harden_ssh_client_crypto_policy_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 107 | ······<ocil:title>Harden·SSH·client·Crypto·Policy</ocil:title> |
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-harden_ssh_client_crypto_policy_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg- | 112 | ····<ocil:questionnaire·id="ocil:ssg-no_host_based_files_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 113 | ······<ocil:title>Remove·Host-Based·Authentication·Files</ocil:title> |
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-no_host_based_files_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_ocil:questionnaire:1"> | ||
119 | ···· | 118 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_max_life_existing_ocil:questionnaire:1"> |
119 | ······<ocil:title>Set·Existing·Passwords·Maximum·Age</ocil:title> | ||
120 | ······<ocil:actions> | 120 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg-a | 121 | ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_existing_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 122 | ······</ocil:actions> |
123 | ····</ocil:questionnaire> | 123 | ····</ocil:questionnaire> |
124 | ····<ocil:questionnaire·id="ocil:ssg-sshd_x11_use_localhost_ocil:questionnaire:1"> | ||
Max diff block lines reached; 2053362/2066189 bytes (99.38%) of diff not shown. |
Offset 19, 15 lines modified | Offset 19, 15 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:harden:"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:harden:"> |
29 | ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Harden·distribution</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Harden·distribution</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_oeharden:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_oeharden:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:nodistro:"> | 32 | ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:nodistro:"> |
33 | ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·nodistro</cpe-dict:title> | 33 | ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·nodistro</cpe-dict:title> |
Offset 39, 15 lines modified | Offset 39, 15 lines modified | ||
39 | ······</cpe-dict:cpe-item> | 39 | ······</cpe-dict:cpe-item> |
40 | ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:poky:"> | 40 | ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:poky:"> |
41 | ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Poky·reference·distribution</cpe-dict:title> | 41 | ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Poky·reference·distribution</cpe-dict:title> |
42 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_poky:def:1</cpe-dict:check> | 42 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_poky:def:1</cpe-dict:check> |
43 | ······</cpe-dict:cpe-item> | 43 | ······</cpe-dict:cpe-item> |
44 | ····</cpe-dict:cpe-list> | 44 | ····</cpe-dict:cpe-list> |
45 | ··</ds:component> | 45 | ··</ds:component> |
46 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-xccdf.xml"·timestamp="2025-0 | 46 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
47 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEMBEDDED"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 47 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEMBEDDED"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
48 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 48 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
49 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·OpenEmbedded</xccdf-1.2:title> | 49 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·OpenEmbedded</xccdf-1.2:title> |
50 | ······<xccdf-1.2:description> | 50 | ······<xccdf-1.2:description> |
51 | ········This·guide·presents·a·catalog·of·security-relevant | 51 | ········This·guide·presents·a·catalog·of·security-relevant |
52 | configuration·settings·for·OpenEmbedded.·It·is·a·rendering·of | 52 | configuration·settings·for·OpenEmbedded.·It·is·a·rendering·of |
53 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 53 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 59078, 15 lines modified | Offset 59078, 15 lines modified | ||
59078 | ··············<xccdf-1.2:check-content-ref·href="ssg-openembedded-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> | 59078 | ··············<xccdf-1.2:check-content-ref·href="ssg-openembedded-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> |
59079 | ············</xccdf-1.2:check> | 59079 | ············</xccdf-1.2:check> |
59080 | ··········</xccdf-1.2:Rule> | 59080 | ··········</xccdf-1.2:Rule> |
59081 | ········</xccdf-1.2:Group> | 59081 | ········</xccdf-1.2:Group> |
59082 | ······</xccdf-1.2:Group> | 59082 | ······</xccdf-1.2:Group> |
59083 | ····</xccdf-1.2:Benchmark> | 59083 | ····</xccdf-1.2:Benchmark> |
59084 | ··</ds:component> | 59084 | ··</ds:component> |
59085 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-oval.xml"·timestamp="2025-0 | 59085 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-oval.xml"·timestamp="2025-03-01T22:08:00"> |
59086 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 59086 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
59087 | ······<oval-def:generator> | 59087 | ······<oval-def:generator> |
59088 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 59088 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
59089 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 59089 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
59090 | ········<oval:schema_version>5.11</oval:schema_version> | 59090 | ········<oval:schema_version>5.11</oval:schema_version> |
59091 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 59091 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
59092 | ······</oval-def:generator> | 59092 | ······</oval-def:generator> |
Offset 81150, 3634 lines modified | Offset 81150, 3634 lines modified | ||
81150 | ············</oval-def:arithmetic> | 81150 | ············</oval-def:arithmetic> |
81151 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 81151 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
81152 | ··········</oval-def:arithmetic> | 81152 | ··········</oval-def:arithmetic> |
81153 | ········</oval-def:local_variable> | 81153 | ········</oval-def:local_variable> |
81154 | ······</oval-def:variables> | 81154 | ······</oval-def:variables> |
81155 | ····</oval-def:oval_definitions> | 81155 | ····</oval-def:oval_definitions> |
81156 | ··</ds:component> | 81156 | ··</ds:component> |
81157 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-ocil.xml"·timestamp="2025-0 | 81157 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
81158 | ····<ocil:ocil> | 81158 | ····<ocil:ocil> |
81159 | ······<ocil:generator> | 81159 | ······<ocil:generator> |
81160 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 81160 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
81161 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 81161 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
81162 | ········<ocil:schema_version>2.0</ocil:schema_version> | 81162 | ········<ocil:schema_version>2.0</ocil:schema_version> |
81163 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 81163 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
81164 | ······</ocil:generator> | 81164 | ······</ocil:generator> |
81165 | ······<ocil:questionnaires> | 81165 | ······<ocil:questionnaires> |
81166 | ········<ocil:questionnaire·id="ocil:ssg-a | 81166 | ········<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1"> |
81167 | ··········<ocil:title> | 81167 | ··········<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title> |
81168 | ··········<ocil:actions> | 81168 | ··········<ocil:actions> |
81169 | ············<ocil:test_action_ref>ocil:ssg-a | 81169 | ············<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref> |
81170 | ··········</ocil:actions> | 81170 | ··········</ocil:actions> |
81171 | ········</ocil:questionnaire> | 81171 | ········</ocil:questionnaire> |
81172 | ········<ocil:questionnaire·id="ocil:ssg- | 81172 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_gshadow_ocil:questionnaire:1"> |
81173 | ··········<ocil:title> | 81173 | ··········<ocil:title>Verify·Group·Who·Owns·gshadow·File</ocil:title> |
81174 | ··········<ocil:actions> | 81174 | ··········<ocil:actions> |
81175 | ············<ocil:test_action_ref>ocil:ssg- | 81175 | ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_gshadow_action:testaction:1</ocil:test_action_ref> |
81176 | ··········</ocil:actions> | 81176 | ··········</ocil:actions> |
81177 | ········</ocil:questionnaire> | 81177 | ········</ocil:questionnaire> |
81178 | ········<ocil:questionnaire·id="ocil:ssg- | 81178 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_ocil:questionnaire:1"> |
81179 | ··········<ocil:title> | 81179 | ··········<ocil:title>Configure·Response·Mode·of·ARP·Requests·for·All·IPv4·Interfaces</ocil:title> |
81180 | ··········<ocil:actions> | 81180 | ··········<ocil:actions> |
81181 | ············<ocil:test_action_ref>ocil:ssg- | 81181 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_action:testaction:1</ocil:test_action_ref> |
81182 | ··········</ocil:actions> | 81182 | ··········</ocil:actions> |
81183 | ········</ocil:questionnaire> | 81183 | ········</ocil:questionnaire> |
81184 | ········<ocil:questionnaire·id="ocil:ssg- | 81184 | ········<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1"> |
81185 | ··········<ocil:title> | 81185 | ··········<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title> |
81186 | ··········<ocil:actions> | 81186 | ··········<ocil:actions> |
81187 | ············<ocil:test_action_ref>ocil:ssg- | 81187 | ············<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref> |
81188 | ··········</ocil:actions> | 81188 | ··········</ocil:actions> |
81189 | ········</ocil:questionnaire> | 81189 | ········</ocil:questionnaire> |
81190 | ········<ocil:questionnaire·id="ocil:ssg- | 81190 | ········<ocil:questionnaire·id="ocil:ssg-kernel_module_rds_disabled_ocil:questionnaire:1"> |
81191 | ··········<ocil:title> | 81191 | ··········<ocil:title>Disable·RDS·Support</ocil:title> |
81192 | ··········<ocil:actions> | 81192 | ··········<ocil:actions> |
81193 | ············<ocil:test_action_ref>ocil:ssg- | 81193 | ············<ocil:test_action_ref>ocil:ssg-kernel_module_rds_disabled_action:testaction:1</ocil:test_action_ref> |
81194 | ··········</ocil:actions> | 81194 | ··········</ocil:actions> |
81195 | ········</ocil:questionnaire> | 81195 | ········</ocil:questionnaire> |
81196 | ········<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1"> | ||
81197 | ········ | 81196 | ········<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1"> |
81197 | ··········<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title> | ||
81198 | ··········<ocil:actions> | 81198 | ··········<ocil:actions> |
81199 | ············<ocil:test_action_ref>ocil:ssg- | 81199 | ············<ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref> |
81200 | ··········</ocil:actions> | 81200 | ··········</ocil:actions> |
81201 | ········</ocil:questionnaire> | 81201 | ········</ocil:questionnaire> |
81202 | ········<ocil:questionnaire·id="ocil:ssg- | 81202 | ········<ocil:questionnaire·id="ocil:ssg-service_crond_enabled_ocil:questionnaire:1"> |
81203 | ··········<ocil:title> | 81203 | ··········<ocil:title>Enable·cron·Service</ocil:title> |
81204 | ··········<ocil:actions> | 81204 | ··········<ocil:actions> |
81205 | ············<ocil:test_action_ref>ocil:ssg- | 81205 | ············<ocil:test_action_ref>ocil:ssg-service_crond_enabled_action:testaction:1</ocil:test_action_ref> |
81206 | ··········</ocil:actions> | 81206 | ··········</ocil:actions> |
81207 | ········</ocil:questionnaire> | 81207 | ········</ocil:questionnaire> |
81208 | ········<ocil:questionnaire·id="ocil:ssg- | 81208 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_hourly_ocil:questionnaire:1"> |
81209 | ··········<ocil:title> | 81209 | ··········<ocil:title>Verify·Permissions·on·cron.hourly</ocil:title> |
81210 | ··········<ocil:actions> | 81210 | ··········<ocil:actions> |
81211 | ············<ocil:test_action_ref>ocil:ssg- | 81211 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_cron_hourly_action:testaction:1</ocil:test_action_ref> |
81212 | ··········</ocil:actions> | 81212 | ··········</ocil:actions> |
81213 | ········</ocil:questionnaire> | 81213 | ········</ocil:questionnaire> |
81214 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1"> | ||
81215 | ········ | 81214 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_syslog_ocil:questionnaire:1"> |
81215 | ··········<ocil:title>Verify·Group·Who·Owns·/var/log/syslog·File</ocil:title> | ||
81216 | ··········<ocil:actions> | 81216 | ··········<ocil:actions> |
81217 | ············<ocil:test_action_ref>ocil:ssg- | 81217 | ············<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_syslog_action:testaction:1</ocil:test_action_ref> |
81218 | ··········</ocil:actions> | 81218 | ··········</ocil:actions> |
81219 | ········</ocil:questionnaire> | 81219 | ········</ocil:questionnaire> |
81220 | ········<ocil:questionnaire·id="ocil:ssg- | 81220 | ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1"> |
81221 | ··········<ocil:title>Ensure· | 81221 | ··········<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title> |
81222 | ··········<ocil:actions> | 81222 | ··········<ocil:actions> |
81223 | ············<ocil:test_action_ref>ocil:ssg- | 81223 | ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref> |
81224 | ··········</ocil:actions> | 81224 | ··········</ocil:actions> |
81225 | ········</ocil:questionnaire> | 81225 | ········</ocil:questionnaire> |
81226 | ········<ocil:questionnaire·id="ocil:ssg- | 81226 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1"> |
Max diff block lines reached; 948856/960930 bytes (98.74%) of diff not shown. |
Offset 3, 3625 lines modified | Offset 3, 3625 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-a | 10 | ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1"> |
11 | ······<ocil:title> | 11 | ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title> |
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg-a | 13 | ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg- | 16 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_gshadow_ocil:questionnaire:1"> |
17 | ······<ocil:title> | 17 | ······<ocil:title>Verify·Group·Who·Owns·gshadow·File</ocil:title> |
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_gshadow_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_ocil:questionnaire:1"> |
23 | ······<ocil:title> | 23 | ······<ocil:title>Configure·Response·Mode·of·ARP·Requests·for·All·IPv4·Interfaces</ocil:title> |
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg- | 28 | ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1"> |
29 | ······<ocil:title> | 29 | ······<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title> |
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-kernel_module_rds_disabled_ocil:questionnaire:1"> |
35 | ······<ocil:title> | 35 | ······<ocil:title>Disable·RDS·Support</ocil:title> |
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-kernel_module_rds_disabled_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1"> | ||
41 | ···· | 40 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1"> |
41 | ······<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title> | ||
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg- | 46 | ····<ocil:questionnaire·id="ocil:ssg-service_crond_enabled_ocil:questionnaire:1"> |
47 | ······<ocil:title> | 47 | ······<ocil:title>Enable·cron·Service</ocil:title> |
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-service_crond_enabled_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 52 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_hourly_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 53 | ······<ocil:title>Verify·Permissions·on·cron.hourly</ocil:title> |
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_hourly_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1"> | ||
59 | ···· | 58 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_syslog_ocil:questionnaire:1"> |
59 | ······<ocil:title>Verify·Group·Who·Owns·/var/log/syslog·File</ocil:title> | ||
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_syslog_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1"> |
65 | ······<ocil:title>Ensure· | 65 | ······<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title> |
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 71 | ······<ocil:title>Verify·Permissions·on·/etc/at.allow·file</ocil:title> |
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_at_allow_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg- | 76 | ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1"> |
77 | ······<ocil:title> | 77 | ······<ocil:title>Set·Password·Minimum·Age</ocil:title> |
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_poweroff_ocil:questionnaire:1"> | ||
83 | ···· | 82 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_x86_vsyscall_emulation_ocil:questionnaire:1"> |
83 | ······<ocil:title>Disable·x86·vsyscall·emulation</ocil:title> | ||
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_x86_vsyscall_emulation_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-file_ | 88 | ····<ocil:questionnaire·id="ocil:ssg-file_cron_deny_not_exist_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 89 | ······<ocil:title>Ensure·that·/etc/cron.deny·does·not·exist</ocil:title> |
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg-file_ | 91 | ········<ocil:test_action_ref>ocil:ssg-file_cron_deny_not_exist_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg- | 94 | ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 95 | ······<ocil:title>Modify·the·System·Login·Banner</ocil:title> |
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_d_ocil:questionnaire:1"> |
101 | ······<ocil:title> | 101 | ······<ocil:title>Verify·Group·Who·Owns·cron.d</ocil:title> |
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_d_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg- | 106 | ····<ocil:questionnaire·id="ocil:ssg-package_MFEhiplsm_installed_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 107 | ······<ocil:title>Install·the·Host·Intrusion·Prevention·System·(HIPS)·Module</ocil:title> |
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-package_MFEhiplsm_installed_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-sshd_ | 112 | ····<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 113 | ······<ocil:title>Do·Not·Allow·SSH·Environment·Options</ocil:title> |
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg-sshd_ | 115 | ········<ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg- | 118 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1"> |
119 | ······<ocil:title> | 119 | ······<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title> |
120 | ······<ocil:actions> | 120 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg- | 121 | ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 122 | ······</ocil:actions> |
123 | ····</ocil:questionnaire> | 123 | ····</ocil:questionnaire> |
124 | ····<ocil:questionnaire·id="ocil:ssg- | 124 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_renameat_ocil:questionnaire:1"> |
125 | ······<ocil:title>Ena | 125 | ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·renameat</ocil:title> |
126 | ······<ocil:actions> | 126 | ······<ocil:actions> |
Max diff block lines reached; 902618/915556 bytes (98.59%) of diff not shown. |
Offset 19, 15 lines modified | Offset 19, 15 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS:ga:server"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS:ga:server"> |
29 | ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP1:ga:server"> | 32 | ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP1:ga:server"> |
33 | ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP1</cpe-dict:title> | 33 | ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP1</cpe-dict:title> |
Offset 35, 15 lines modified | Offset 35, 15 lines modified | ||
35 | ······</cpe-dict:cpe-item> | 35 | ······</cpe-dict:cpe-item> |
36 | ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP2:ga:server"> | 36 | ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP2:ga:server"> |
37 | ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP2</cpe-dict:title> | 37 | ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP2</cpe-dict:title> |
38 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check> | 38 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check> |
39 | ······</cpe-dict:cpe-item> | 39 | ······</cpe-dict:cpe-item> |
40 | ····</cpe-dict:cpe-list> | 40 | ····</cpe-dict:cpe-list> |
41 | ··</ds:component> | 41 | ··</ds:component> |
42 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-xccdf.xml"·timestamp="2025-0 | 42 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
43 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEULER2203"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 43 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEULER2203"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
44 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 44 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
45 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openEuler·2203</xccdf-1.2:title> | 45 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openEuler·2203</xccdf-1.2:title> |
46 | ······<xccdf-1.2:description> | 46 | ······<xccdf-1.2:description> |
47 | ········This·guide·presents·a·catalog·of·security-relevant | 47 | ········This·guide·presents·a·catalog·of·security-relevant |
48 | configuration·settings·for·openEuler·2203.·It·is·a·rendering·of | 48 | configuration·settings·for·openEuler·2203.·It·is·a·rendering·of |
49 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 49 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 39461, 15 lines modified | Offset 39461, 15 lines modified | ||
39461 | ··············<xccdf-1.2:check-content-ref·href="ssg-openeuler2203-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"/> | 39461 | ··············<xccdf-1.2:check-content-ref·href="ssg-openeuler2203-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"/> |
39462 | ············</xccdf-1.2:check> | 39462 | ············</xccdf-1.2:check> |
39463 | ··········</xccdf-1.2:Rule> | 39463 | ··········</xccdf-1.2:Rule> |
39464 | ········</xccdf-1.2:Group> | 39464 | ········</xccdf-1.2:Group> |
39465 | ······</xccdf-1.2:Group> | 39465 | ······</xccdf-1.2:Group> |
39466 | ····</xccdf-1.2:Benchmark> | 39466 | ····</xccdf-1.2:Benchmark> |
39467 | ··</ds:component> | 39467 | ··</ds:component> |
39468 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"·timestamp="2025-0 | 39468 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"·timestamp="2025-03-01T22:08:00"> |
39469 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 39469 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
39470 | ······<oval-def:generator> | 39470 | ······<oval-def:generator> |
39471 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 39471 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
39472 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 39472 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
39473 | ········<oval:schema_version>5.11</oval:schema_version> | 39473 | ········<oval:schema_version>5.11</oval:schema_version> |
39474 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 39474 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
39475 | ······</oval-def:generator> | 39475 | ······</oval-def:generator> |
Offset 52232, 4510 lines modified | Offset 52232, 4586 lines modified | ||
52232 | ············</oval-def:arithmetic> | 52232 | ············</oval-def:arithmetic> |
52233 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 52233 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
52234 | ··········</oval-def:arithmetic> | 52234 | ··········</oval-def:arithmetic> |
52235 | ········</oval-def:local_variable> | 52235 | ········</oval-def:local_variable> |
52236 | ······</oval-def:variables> | 52236 | ······</oval-def:variables> |
52237 | ····</oval-def:oval_definitions> | 52237 | ····</oval-def:oval_definitions> |
52238 | ··</ds:component> | 52238 | ··</ds:component> |
52239 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"·timestamp="2025-0 | 52239 | ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
52240 | ····<ocil:ocil> | 52240 | ····<ocil:ocil> |
52241 | ······<ocil:generator> | 52241 | ······<ocil:generator> |
52242 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 52242 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
52243 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 52243 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
52244 | ········<ocil:schema_version>2.0</ocil:schema_version> | 52244 | ········<ocil:schema_version>2.0</ocil:schema_version> |
52245 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 52245 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
52246 | ······</ocil:generator> | 52246 | ······</ocil:generator> |
52247 | ······<ocil:questionnaires> | 52247 | ······<ocil:questionnaires> |
52248 | ········<ocil:questionnaire·id="ocil:ssg-a | 52248 | ········<ocil:questionnaire·id="ocil:ssg-accounts_tmout_ocil:questionnaire:1"> |
52249 | ··········<ocil:title>Set·Interactive·Session·Timeout</ocil:title> | ||
52249 | ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title> | ||
52250 | ··········<ocil:actions> | ||
52251 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref> | ||
52252 | ··········</ocil:actions> | ||
52253 | ········</ocil:questionnaire> | ||
52254 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1"> | ||
52255 | ··········<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title> | ||
52256 | ··········<ocil:actions> | ||
52257 | ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref> | ||
52258 | ··········</ocil:actions> | ||
52259 | ········</ocil:questionnaire> | ||
52260 | ········<ocil:questionnaire·id="ocil:ssg-set_nftables_loopback_traffic_ocil:questionnaire:1"> | ||
52261 | ··········<ocil:title>Set·nftables·Configuration·for·Loopback·Traffic</ocil:title> | ||
52262 | ··········<ocil:actions> | 52250 | ··········<ocil:actions> |
52263 | ············<ocil:test_action_ref>ocil:ssg- | 52251 | ············<ocil:test_action_ref>ocil:ssg-accounts_tmout_action:testaction:1</ocil:test_action_ref> |
52264 | ··········</ocil:actions> | 52252 | ··········</ocil:actions> |
52265 | ········</ocil:questionnaire> | 52253 | ········</ocil:questionnaire> |
52266 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_ | 52254 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1"> |
52267 | ··········<ocil:title>Verify· | 52255 | ··········<ocil:title>Verify·Owner·on·cron.monthly</ocil:title> |
52268 | ··········<ocil:actions> | 52256 | ··········<ocil:actions> |
52269 | ············<ocil:test_action_ref>ocil:ssg-file_owner_ | 52257 | ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref> |
52270 | ··········</ocil:actions> | 52258 | ··········</ocil:actions> |
52271 | ········</ocil:questionnaire> | 52259 | ········</ocil:questionnaire> |
52272 | ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ucredit_ocil:questionnaire:1"> | ||
52273 | ········ | 52260 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1"> |
52261 | ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title> | ||
52274 | ··········<ocil:actions> | 52262 | ··········<ocil:actions> |
52275 | ············<ocil:test_action_ref>ocil:ssg- | 52263 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref> |
52276 | ··········</ocil:actions> | 52264 | ··········</ocil:actions> |
52277 | ········</ocil:questionnaire> | 52265 | ········</ocil:questionnaire> |
52278 | ········<ocil:questionnaire·id="ocil:ssg- | 52266 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_hourly_ocil:questionnaire:1"> |
52279 | ··········<ocil:title> | 52267 | ··········<ocil:title>Verify·Owner·on·cron.hourly</ocil:title> |
52280 | ··········<ocil:actions> | 52268 | ··········<ocil:actions> |
52281 | ············<ocil:test_action_ref>ocil:ssg- | 52269 | ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_hourly_action:testaction:1</ocil:test_action_ref> |
52282 | ··········</ocil:actions> | 52270 | ··········</ocil:actions> |
52283 | ········</ocil:questionnaire> | 52271 | ········</ocil:questionnaire> |
52284 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fsetxattr_ocil:questionnaire:1"> | ||
52285 | ········ | 52272 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_weekly_ocil:questionnaire:1"> |
52273 | ··········<ocil:title>Verify·Group·Who·Owns·cron.weekly</ocil:title> | ||
52286 | ··········<ocil:actions> | 52274 | ··········<ocil:actions> |
52287 | ············<ocil:test_action_ref>ocil:ssg- | 52275 | ············<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_weekly_action:testaction:1</ocil:test_action_ref> |
52288 | ··········</ocil:actions> | 52276 | ··········</ocil:actions> |
52289 | ········</ocil:questionnaire> | 52277 | ········</ocil:questionnaire> |
52290 | ········<ocil:questionnaire·id="ocil:ssg- | 52278 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_insmod_ocil:questionnaire:1"> |
52291 | ··········<ocil:title> | 52279 | ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·insmod</ocil:title> |
52292 | ··········<ocil:actions> | 52280 | ··········<ocil:actions> |
52293 | ············<ocil:test_action_ref>ocil:ssg- | 52281 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_insmod_action:testaction:1</ocil:test_action_ref> |
52294 | ··········</ocil:actions> | 52282 | ··········</ocil:actions> |
52295 | ········</ocil:questionnaire> | 52283 | ········</ocil:questionnaire> |
52296 | ········<ocil:questionnaire·id="ocil:ssg- | 52284 | ········<ocil:questionnaire·id="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1"> |
52297 | ··········<ocil:title> | 52285 | ··········<ocil:title>Verify·firewalld·Enabled</ocil:title> |
52298 | ··········<ocil:actions> | 52286 | ··········<ocil:actions> |
52299 | ············<ocil:test_action_ref>ocil:ssg- | 52287 | ············<ocil:test_action_ref>ocil:ssg-service_firewalld_enabled_action:testaction:1</ocil:test_action_ref> |
52300 | ··········</ocil:actions> | 52288 | ··········</ocil:actions> |
52301 | ········</ocil:questionnaire> | 52289 | ········</ocil:questionnaire> |
52302 | ········<ocil:questionnaire·id="ocil:ssg- | 52290 | ········<ocil:questionnaire·id="ocil:ssg-package_httpd_removed_ocil:questionnaire:1"> |
52303 | ··········<ocil:title> | 52291 | ··········<ocil:title>Uninstall·httpd·Package</ocil:title> |
52304 | ··········<ocil:actions> | 52292 | ··········<ocil:actions> |
52305 | ············<ocil:test_action_ref>ocil:ssg- | 52293 | ············<ocil:test_action_ref>ocil:ssg-package_httpd_removed_action:testaction:1</ocil:test_action_ref> |
52306 | ··········</ocil:actions> | 52294 | ··········</ocil:actions> |
52307 | ········</ocil:questionnaire> | 52295 | ········</ocil:questionnaire> |
Max diff block lines reached; 562044/573602 bytes (97.99%) of diff not shown. |
Offset 3, 4501 lines modified | Offset 3, 4577 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-a | 10 | ····<ocil:questionnaire·id="ocil:ssg-accounts_tmout_ocil:questionnaire:1"> |
11 | ······<ocil:title>Set·Interactive·Session·Timeout</ocil:title> | ||
11 | ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1"> | ||
17 | ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title> | ||
18 | ······<ocil:actions> | ||
19 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref> | ||
20 | ······</ocil:actions> | ||
21 | ····</ocil:questionnaire> | ||
22 | ····<ocil:questionnaire·id="ocil:ssg-set_nftables_loopback_traffic_ocil:questionnaire:1"> | ||
23 | ······<ocil:title>Set·nftables·Configuration·for·Loopback·Traffic</ocil:title> | ||
24 | ······<ocil:actions> | 12 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-accounts_tmout_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 14 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_ | 16 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1"> |
29 | ······<ocil:title>Verify· | 17 | ······<ocil:title>Verify·Owner·on·cron.monthly</ocil:title> |
30 | ······<ocil:actions> | 18 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg-file_owner_ | 19 | ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 20 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ucredit_ocil:questionnaire:1"> | ||
35 | ···· | 22 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1"> |
23 | ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title> | ||
36 | ······<ocil:actions> | 24 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 26 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 28 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_hourly_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 29 | ······<ocil:title>Verify·Owner·on·cron.hourly</ocil:title> |
42 | ······<ocil:actions> | 30 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_hourly_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 32 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fsetxattr_ocil:questionnaire:1"> | ||
47 | ···· | 34 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_weekly_ocil:questionnaire:1"> |
35 | ······<ocil:title>Verify·Group·Who·Owns·cron.weekly</ocil:title> | ||
48 | ······<ocil:actions> | 36 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_weekly_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 38 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-package_telnet-server_removed_ocil:questionnaire:1"> | ||
53 | ···· | 40 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_insmod_ocil:questionnaire:1"> |
41 | ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·insmod</ocil:title> | ||
54 | ······<ocil:actions> | 42 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_insmod_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 44 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg- | 46 | ····<ocil:questionnaire·id="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 47 | ······<ocil:title>Verify·firewalld·Enabled</ocil:title> |
60 | ······<ocil:actions> | 48 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-service_firewalld_enabled_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 50 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fremovexattr_ocil:questionnaire:1"> | ||
65 | ···· | 52 | ····<ocil:questionnaire·id="ocil:ssg-package_httpd_removed_ocil:questionnaire:1"> |
53 | ······<ocil:title>Uninstall·httpd·Package</ocil:title> | ||
66 | ······<ocil:actions> | 54 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-package_httpd_removed_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 56 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_ | 58 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1"> |
71 | ······<ocil:title>Disable· | 59 | ······<ocil:title>Disable·X11·Forwarding</ocil:title> |
72 | ······<ocil:actions> | 60 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_ | 61 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 62 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-package_aide_installed_ocil:questionnaire:1"> |
77 | ······<ocil:title> | 65 | ······<ocil:title>Install·AIDE</ocil:title> |
78 | ······<ocil:actions> | 66 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 68 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 71 | ······<ocil:title>Deactivate·Wireless·Network·Interfaces</ocil:title> |
84 | ······<ocil:actions> | 72 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 74 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1"> | ||
89 | ···· | 76 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1"> |
77 | ······<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title> | ||
90 | ······<ocil:actions> | 78 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 80 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg- | 82 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 83 | ······<ocil:title>Verify·Permissions·on·/etc/at.allow·file</ocil:title> |
96 | ······<ocil:actions> | 84 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_at_allow_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 86 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg- | 88 | ····<ocil:questionnaire·id="ocil:ssg-set_loopback_traffic_ocil:questionnaire:1"> |
101 | ······<ocil:title> | 89 | ······<ocil:title>Set·configuration·for·loopback·traffic</ocil:title> |
102 | ······<ocil:actions> | 90 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-set_loopback_traffic_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 92 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_chown_ocil:questionnaire:1"> | ||
107 | ···· | 94 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_ocil:questionnaire:1"> |
95 | ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv6·Interfaces</ocil:title> | ||
108 | ······<ocil:actions> | 96 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 98 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1"> | ||
113 | ···· | 100 | ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1"> |
101 | ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title> | ||
114 | ······<ocil:actions> | 102 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 104 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-audit | 106 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_unlink_ocil:questionnaire:1"> |
119 | ······<ocil:title> | 107 | ······<ocil:title>Record·Successful·Delete·Attempts·to·Files·-·unlink</ocil:title> |
120 | ······<ocil:actions> | 108 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg-audit | 109 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_unlink_action:testaction:1</ocil:test_action_ref> |
Max diff block lines reached; 532503/544258 bytes (97.84%) of diff not shown. |
Offset 19, 15 lines modified | Offset 19, 15 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:15.0"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:15.0"> |
29 | ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·15.0</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·15.0</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap15:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap15:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.1"> | 32 | ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.1"> |
33 | ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.1</cpe-dict:title> | 33 | ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.1</cpe-dict:title> |
Offset 39, 15 lines modified | Offset 39, 15 lines modified | ||
39 | ······</cpe-dict:cpe-item> | 39 | ······</cpe-dict:cpe-item> |
40 | ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.3"> | 40 | ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.3"> |
41 | ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.3</cpe-dict:title> | 41 | ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.3</cpe-dict:title> |
42 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap42:def:1</cpe-dict:check> | 42 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap42:def:1</cpe-dict:check> |
43 | ······</cpe-dict:cpe-item> | 43 | ······</cpe-dict:cpe-item> |
44 | ····</cpe-dict:cpe-list> | 44 | ····</cpe-dict:cpe-list> |
45 | ··</ds:component> | 45 | ··</ds:component> |
46 | ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-xccdf.xml"·timestamp="2025-0 | 46 | ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
47 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENSUSE"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 47 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENSUSE"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
48 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 48 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
49 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openSUSE</xccdf-1.2:title> | 49 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openSUSE</xccdf-1.2:title> |
50 | ······<xccdf-1.2:description> | 50 | ······<xccdf-1.2:description> |
51 | ········This·guide·presents·a·catalog·of·security-relevant | 51 | ········This·guide·presents·a·catalog·of·security-relevant |
52 | configuration·settings·for·openSUSE.·It·is·a·rendering·of | 52 | configuration·settings·for·openSUSE.·It·is·a·rendering·of |
53 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 53 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 41119, 15 lines modified | Offset 41119, 15 lines modified | ||
41119 | ··············<xccdf-1.2:check-content-ref·href="ssg-opensuse-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> | 41119 | ··············<xccdf-1.2:check-content-ref·href="ssg-opensuse-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> |
41120 | ············</xccdf-1.2:check> | 41120 | ············</xccdf-1.2:check> |
41121 | ··········</xccdf-1.2:Rule> | 41121 | ··········</xccdf-1.2:Rule> |
41122 | ········</xccdf-1.2:Group> | 41122 | ········</xccdf-1.2:Group> |
41123 | ······</xccdf-1.2:Group> | 41123 | ······</xccdf-1.2:Group> |
41124 | ····</xccdf-1.2:Benchmark> | 41124 | ····</xccdf-1.2:Benchmark> |
41125 | ··</ds:component> | 41125 | ··</ds:component> |
41126 | ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-oval.xml"·timestamp="2025-0 | 41126 | ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-oval.xml"·timestamp="2025-03-01T22:08:00"> |
41127 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 41127 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
41128 | ······<oval-def:generator> | 41128 | ······<oval-def:generator> |
41129 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 41129 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
41130 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 41130 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
41131 | ········<oval:schema_version>5.11</oval:schema_version> | 41131 | ········<oval:schema_version>5.11</oval:schema_version> |
41132 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 41132 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
41133 | ······</oval-def:generator> | 41133 | ······</oval-def:generator> |
Offset 56631, 2714 lines modified | Offset 56631, 2714 lines modified | ||
56631 | ············</oval-def:arithmetic> | 56631 | ············</oval-def:arithmetic> |
56632 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 56632 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
56633 | ··········</oval-def:arithmetic> | 56633 | ··········</oval-def:arithmetic> |
56634 | ········</oval-def:local_variable> | 56634 | ········</oval-def:local_variable> |
56635 | ······</oval-def:variables> | 56635 | ······</oval-def:variables> |
56636 | ····</oval-def:oval_definitions> | 56636 | ····</oval-def:oval_definitions> |
56637 | ··</ds:component> | 56637 | ··</ds:component> |
56638 | ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-ocil.xml"·timestamp="2025-0 | 56638 | ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
56639 | ····<ocil:ocil> | 56639 | ····<ocil:ocil> |
56640 | ······<ocil:generator> | 56640 | ······<ocil:generator> |
56641 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 56641 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
56642 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 56642 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
56643 | ········<ocil:schema_version>2.0</ocil:schema_version> | 56643 | ········<ocil:schema_version>2.0</ocil:schema_version> |
56644 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 56644 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
56645 | ······</ocil:generator> | 56645 | ······</ocil:generator> |
56646 | ······<ocil:questionnaires> | 56646 | ······<ocil:questionnaires> |
56647 | ········<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1"> | ||
56648 | ········ | 56647 | ········<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1"> |
56648 | ··········<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title> | ||
56649 | ··········<ocil:actions> | 56649 | ··········<ocil:actions> |
56650 | ············<ocil:test_action_ref>ocil:ssg- | 56650 | ············<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref> |
56651 | ··········</ocil:actions> | 56651 | ··········</ocil:actions> |
56652 | ········</ocil:questionnaire> | 56652 | ········</ocil:questionnaire> |
56653 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_ | 56653 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_notifiers_ocil:questionnaire:1"> |
56654 | ··········<ocil:title>Enable·checks·on· | 56654 | ··········<ocil:title>Enable·checks·on·notifier·call·chains</ocil:title> |
56655 | ··········<ocil:actions> | 56655 | ··········<ocil:actions> |
56656 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_ | 56656 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_notifiers_action:testaction:1</ocil:test_action_ref> |
56657 | ··········</ocil:actions> | 56657 | ··········</ocil:actions> |
56658 | ········</ocil:questionnaire> | 56658 | ········</ocil:questionnaire> |
56659 | ········<ocil:questionnaire·id="ocil:ssg- | 56659 | ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1"> |
56660 | ··········<ocil:title> | 56660 | ··········<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title> |
56661 | ··········<ocil:actions> | 56661 | ··········<ocil:actions> |
56662 | ············<ocil:test_action_ref>ocil:ssg- | 56662 | ············<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref> |
56663 | ··········</ocil:actions> | 56663 | ··········</ocil:actions> |
56664 | ········</ocil:questionnaire> | 56664 | ········</ocil:questionnaire> |
56665 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1"> | ||
56666 | ········ | 56665 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_syslog_ocil:questionnaire:1"> |
56666 | ··········<ocil:title>Verify·Permissions·on·/var/log/syslog·File</ocil:title> | ||
56667 | ··········<ocil:actions> | 56667 | ··········<ocil:actions> |
56668 | ············<ocil:test_action_ref>ocil:ssg- | 56668 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_syslog_action:testaction:1</ocil:test_action_ref> |
56669 | ··········</ocil:actions> | 56669 | ··········</ocil:actions> |
56670 | ········</ocil:questionnaire> | 56670 | ········</ocil:questionnaire> |
56671 | ········<ocil:questionnaire·id="ocil:ssg- | 56671 | ········<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1"> |
56672 | ··········<ocil:title> | 56672 | ··········<ocil:title>Enable·auditd·Service</ocil:title> |
56673 | ··········<ocil:actions> | 56673 | ··········<ocil:actions> |
56674 | ············<ocil:test_action_ref>ocil:ssg- | 56674 | ············<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref> |
56675 | ··········</ocil:actions> | 56675 | ··········</ocil:actions> |
56676 | ········</ocil:questionnaire> | 56676 | ········</ocil:questionnaire> |
56677 | ········<ocil:questionnaire·id="ocil:ssg- | 56677 | ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1"> |
56678 | ··········<ocil:title> | 56678 | ··········<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title> |
56679 | ··········<ocil:actions> | 56679 | ··········<ocil:actions> |
56680 | ············<ocil:test_action_ref>ocil:ssg- | 56680 | ············<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref> |
56681 | ··········</ocil:actions> | 56681 | ··········</ocil:actions> |
56682 | ········</ocil:questionnaire> | 56682 | ········</ocil:questionnaire> |
56683 | ········<ocil:questionnaire·id="ocil:ssg- | 56683 | ········<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1"> |
56684 | ··········<ocil:title> | 56684 | ··········<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title> |
56685 | ··········<ocil:actions> | 56685 | ··········<ocil:actions> |
56686 | ············<ocil:test_action_ref>ocil:ssg- | 56686 | ············<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref> |
56687 | ··········</ocil:actions> | 56687 | ··········</ocil:actions> |
56688 | ········</ocil:questionnaire> | 56688 | ········</ocil:questionnaire> |
56689 | ········<ocil:questionnaire·id="ocil:ssg- | 56689 | ········<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1"> |
56690 | ··········<ocil:title> | 56690 | ··········<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Root</ocil:title> |
56691 | ··········<ocil:actions> | 56691 | ··········<ocil:actions> |
56692 | ············<ocil:test_action_ref>ocil:ssg- | 56692 | ············<ocil:test_action_ref>ocil:ssg-file_ownership_audit_configuration_action:testaction:1</ocil:test_action_ref> |
56693 | ··········</ocil:actions> | 56693 | ··········</ocil:actions> |
56694 | ········</ocil:questionnaire> | 56694 | ········</ocil:questionnaire> |
56695 | ········<ocil:questionnaire·id="ocil:ssg- | 56695 | ········<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1"> |
56696 | ··········<ocil:title>Ensure· | 56696 | ··········<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title> |
56697 | ··········<ocil:actions> | 56697 | ··········<ocil:actions> |
56698 | ············<ocil:test_action_ref>ocil:ssg- | 56698 | ············<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref> |
56699 | ··········</ocil:actions> | 56699 | ··········</ocil:actions> |
56700 | ········</ocil:questionnaire> | 56700 | ········</ocil:questionnaire> |
56701 | ········<ocil:questionnaire·id="ocil:ssg- | 56701 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1"> |
56702 | ··········<ocil:title> | 56702 | ··········<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·by·Default</ocil:title> |
56703 | ··········<ocil:actions> | 56703 | ··········<ocil:actions> |
56704 | ············<ocil:test_action_ref>ocil:ssg- | 56704 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_action:testaction:1</ocil:test_action_ref> |
56705 | ··········</ocil:actions> | 56705 | ··········</ocil:actions> |
56706 | ········</ocil:questionnaire> | 56706 | ········</ocil:questionnaire> |
56707 | ········<ocil:questionnaire·id="ocil:ssg- | 56707 | ········<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1"> |
Max diff block lines reached; 683761/695719 bytes (98.28%) of diff not shown. |
Offset 3, 2705 lines modified | Offset 3, 2705 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1"> | ||
11 | ···· | 10 | ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1"> |
11 | ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title> | ||
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_ | 16 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_notifiers_ocil:questionnaire:1"> |
17 | ······<ocil:title>Enable·checks·on· | 17 | ······<ocil:title>Enable·checks·on·notifier·call·chains</ocil:title> |
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_ | 19 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_notifiers_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1"> |
23 | ······<ocil:title> | 23 | ······<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title> |
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1"> | ||
29 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_syslog_ocil:questionnaire:1"> |
29 | ······<ocil:title>Verify·Permissions·on·/var/log/syslog·File</ocil:title> | ||
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_syslog_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1"> |
35 | ······<ocil:title> | 35 | ······<ocil:title>Enable·auditd·Service</ocil:title> |
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 40 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 41 | ······<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title> |
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg- | 46 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1"> |
47 | ······<ocil:title> | 47 | ······<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title> |
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 52 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 53 | ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Root</ocil:title> |
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-file_ownership_audit_configuration_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1"> |
59 | ······<ocil:title>Ensure· | 59 | ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title> |
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1"> |
65 | ······<ocil:title> | 65 | ······<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·by·Default</ocil:title> |
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 71 | ······<ocil:title>Disable·Host-Based·Authentication</ocil:title> |
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg- | 76 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nodev_ocil:questionnaire:1"> |
77 | ······<ocil:title> | 77 | ······<ocil:title>Add·nodev·Option·to·/dev/shm</ocil:title> |
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nodev_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg- | 82 | ····<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 83 | ······<ocil:title>The·Chrony·package·is·installed</ocil:title> |
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg- | 88 | ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_ocil:questionnaire:1"> |
89 | ······<ocil:title>Configure· | 89 | ······<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title> |
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg- | 94 | ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 95 | ······<ocil:title>Set·SSH·Client·Alive·Count·Max·to·zero</ocil:title> |
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_0_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-no_all_squash_exports_ocil:questionnaire:1"> |
101 | ······<ocil:title>Ensure· | 101 | ······<ocil:title>Ensure·All-Squashing·Disabled·On·All·Exports</ocil:title> |
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-no_all_squash_exports_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg- | 106 | ····<ocil:questionnaire·id="ocil:ssg-chronyd_server_directive_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 107 | ······<ocil:title>Ensure·Chrony·is·only·configured·with·the·server·directive</ocil:title> |
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-chronyd_server_directive_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1"> | ||
113 | ···· | 112 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1"> |
113 | ······<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title> | ||
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg- | 118 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1"> |
119 | ······<ocil:title> | 119 | ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title> |
120 | ······<ocil:actions> | 120 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg- | 121 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 122 | ······</ocil:actions> |
123 | ····</ocil:questionnaire> | 123 | ····</ocil:questionnaire> |
124 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount2_ocil:questionnaire:1"> | ||
125 | ···· | 124 | ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1"> |
125 | ······<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title> | ||
Max diff block lines reached; 648285/660970 bytes (98.08%) of diff not shown. |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux_coreos:4"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux_coreos:4"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·CoreOS·4</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·CoreOS·4</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml">oval:ssg-installed_OS_is_rhcos4:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml">oval:ssg-installed_OS_is_rhcos4:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHCOS-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHCOS-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Red·Hat·Enterprise·Linux·CoreOS·4.·It·is·a·rendering·of | 40 | configuration·settings·for·Red·Hat·Enterprise·Linux·CoreOS·4.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 321, 23 lines modified | Offset 321, 23 lines modified | ||
321 | ··········</cpe-lang:logical-test> | 321 | ··········</cpe-lang:logical-test> |
322 | ········</cpe-lang:platform> | 322 | ········</cpe-lang:platform> |
323 | ········<cpe-lang:platform·id="package_bash"> | 323 | ········<cpe-lang:platform·id="package_bash"> |
324 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 324 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
325 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> | 325 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> |
326 | ··········</cpe-lang:logical-test> | 326 | ··········</cpe-lang:logical-test> |
327 | ········</cpe-lang:platform> | 327 | ········</cpe-lang:platform> |
328 | ········<cpe-lang:platform·id="os_linux_ | 328 | ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> |
329 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 329 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
330 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ | 330 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> |
331 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> | ||
332 | ··········</cpe-lang:logical-test> | 331 | ··········</cpe-lang:logical-test> |
333 | ········</cpe-lang:platform> | 332 | ········</cpe-lang:platform> |
334 | ········<cpe-lang:platform·id="os_linux_ | 333 | ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0"> |
335 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 334 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
336 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ | 335 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/> |
336 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> | ||
337 | ··········</cpe-lang:logical-test> | 337 | ··········</cpe-lang:logical-test> |
338 | ········</cpe-lang:platform> | 338 | ········</cpe-lang:platform> |
339 | ········<cpe-lang:platform·id="package_tmux"> | 339 | ········<cpe-lang:platform·id="package_tmux"> |
340 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 340 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
341 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_tmux:def:1"/> | 341 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_tmux:def:1"/> |
342 | ··········</cpe-lang:logical-test> | 342 | ··········</cpe-lang:logical-test> |
343 | ········</cpe-lang:platform> | 343 | ········</cpe-lang:platform> |
Offset 66389, 15 lines modified | Offset 66389, 15 lines modified | ||
66389 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhcos4-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/> | 66389 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhcos4-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/> |
66390 | ············</xccdf-1.2:check> | 66390 | ············</xccdf-1.2:check> |
66391 | ··········</xccdf-1.2:Rule> | 66391 | ··········</xccdf-1.2:Rule> |
66392 | ········</xccdf-1.2:Group> | 66392 | ········</xccdf-1.2:Group> |
66393 | ······</xccdf-1.2:Group> | 66393 | ······</xccdf-1.2:Group> |
66394 | ····</xccdf-1.2:Benchmark> | 66394 | ····</xccdf-1.2:Benchmark> |
66395 | ··</ds:component> | 66395 | ··</ds:component> |
66396 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-oval.xml"·timestamp="2025-0 | 66396 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-oval.xml"·timestamp="2025-03-01T22:08:00"> |
66397 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 66397 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
66398 | ······<oval-def:generator> | 66398 | ······<oval-def:generator> |
66399 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 66399 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
66400 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 66400 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
66401 | ········<oval:schema_version>5.11</oval:schema_version> | 66401 | ········<oval:schema_version>5.11</oval:schema_version> |
66402 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 66402 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
66403 | ······</oval-def:generator> | 66403 | ······</oval-def:generator> |
Offset 104700, 8240 lines modified | Offset 104700, 8240 lines modified | ||
104700 | ············</oval-def:arithmetic> | 104700 | ············</oval-def:arithmetic> |
104701 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 104701 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
104702 | ··········</oval-def:arithmetic> | 104702 | ··········</oval-def:arithmetic> |
104703 | ········</oval-def:local_variable> | 104703 | ········</oval-def:local_variable> |
104704 | ······</oval-def:variables> | 104704 | ······</oval-def:variables> |
104705 | ····</oval-def:oval_definitions> | 104705 | ····</oval-def:oval_definitions> |
104706 | ··</ds:component> | 104706 | ··</ds:component> |
104707 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"·timestamp="2025-0 | 104707 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
104708 | ····<ocil:ocil> | 104708 | ····<ocil:ocil> |
104709 | ······<ocil:generator> | 104709 | ······<ocil:generator> |
104710 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 104710 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
104711 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 104711 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
104712 | ········<ocil:schema_version>2.0</ocil:schema_version> | 104712 | ········<ocil:schema_version>2.0</ocil:schema_version> |
104713 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 104713 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
104714 | ······</ocil:generator> | 104714 | ······</ocil:generator> |
104715 | ······<ocil:questionnaires> | 104715 | ······<ocil:questionnaires> |
104716 | ········<ocil:questionnaire·id="ocil:ssg-package_postfix_installed_ocil:questionnaire:1"> | ||
104717 | ········ | 104716 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_chown_ocil:questionnaire:1"> |
104717 | ··········<ocil:title>Record·Unsuccessful·Ownership·Changes·to·Files·-·chown</ocil:title> | ||
104718 | ··········<ocil:actions> | 104718 | ··········<ocil:actions> |
104719 | ············<ocil:test_action_ref>ocil:ssg- | 104719 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_chown_action:testaction:1</ocil:test_action_ref> |
104720 | ··········</ocil:actions> | 104720 | ··········</ocil:actions> |
104721 | ········</ocil:questionnaire> | 104721 | ········</ocil:questionnaire> |
104722 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_gshadow_ocil:questionnaire:1"> | ||
104723 | ········ | 104722 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_sestatus_conf_ocil:questionnaire:1"> |
104723 | ··········<ocil:title>Verify·User·Who·Owns·/etc/sestatus.conf·File</ocil:title> | ||
104724 | ··········<ocil:actions> | 104724 | ··········<ocil:actions> |
104725 | ············<ocil:test_action_ref>ocil:ssg- | 104725 | ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref> |
104726 | ··········</ocil:actions> | 104726 | ··········</ocil:actions> |
104727 | ········</ocil:questionnaire> | 104727 | ········</ocil:questionnaire> |
104728 | ········<ocil:questionnaire·id="ocil:ssg- | 104728 | ········<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1"> |
104729 | ··········<ocil:title> | 104729 | ··········<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title> |
104730 | ··········<ocil:actions> | 104730 | ··········<ocil:actions> |
104731 | ············<ocil:test_action_ref>ocil:ssg- | 104731 | ············<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref> |
104732 | ··········</ocil:actions> | 104732 | ··········</ocil:actions> |
104733 | ········</ocil:questionnaire> | 104733 | ········</ocil:questionnaire> |
104734 | ········<ocil:questionnaire·id="ocil:ssg- | 104734 | ········<ocil:questionnaire·id="ocil:ssg-package_fapolicyd_installed_ocil:questionnaire:1"> |
104735 | ··········<ocil:title> | 104735 | ··········<ocil:title>Install·fapolicyd·Package</ocil:title> |
104736 | ··········<ocil:actions> | 104736 | ··········<ocil:actions> |
104737 | ············<ocil:test_action_ref>ocil:ssg- | 104737 | ············<ocil:test_action_ref>ocil:ssg-package_fapolicyd_installed_action:testaction:1</ocil:test_action_ref> |
104738 | ··········</ocil:actions> | 104738 | ··········</ocil:actions> |
104739 | ········</ocil:questionnaire> | 104739 | ········</ocil:questionnaire> |
104740 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1"> | ||
104741 | ········ | 104740 | ········<ocil:questionnaire·id="ocil:ssg-ensure_redhat_gpgkey_installed_ocil:questionnaire:1"> |
104741 | ··········<ocil:title>Ensure·Red·Hat·GPG·Key·Installed</ocil:title> | ||
104742 | ··········<ocil:actions> | 104742 | ··········<ocil:actions> |
104743 | ············<ocil:test_action_ref>ocil:ssg- | 104743 | ············<ocil:test_action_ref>ocil:ssg-ensure_redhat_gpgkey_installed_action:testaction:1</ocil:test_action_ref> |
104744 | ··········</ocil:actions> | 104744 | ··········</ocil:actions> |
104745 | ········</ocil:questionnaire> | 104745 | ········</ocil:questionnaire> |
104746 | ········<ocil:questionnaire·id="ocil:ssg- | 104746 | ········<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1"> |
104747 | ··········<ocil:title> | 104747 | ··········<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title> |
104748 | ··········<ocil:actions> | 104748 | ··········<ocil:actions> |
104749 | ············<ocil:test_action_ref>ocil:ssg- | 104749 | ············<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref> |
104750 | ··········</ocil:actions> | 104750 | ··········</ocil:actions> |
104751 | ········</ocil:questionnaire> | 104751 | ········</ocil:questionnaire> |
104752 | ········<ocil:questionnaire·id="ocil:ssg- | 104752 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1"> |
104753 | ··········<ocil:title> | 104753 | ··········<ocil:title>Disable·the·IPv6·protocol</ocil:title> |
104754 | ··········<ocil:actions> | 104754 | ··········<ocil:actions> |
104755 | ············<ocil:test_action_ref>ocil:ssg- | 104755 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref> |
104756 | ··········</ocil:actions> | 104756 | ··········</ocil:actions> |
104757 | ········</ocil:questionnaire> | 104757 | ········</ocil:questionnaire> |
104758 | ········<ocil:questionnaire·id="ocil:ssg-mount_option_noexec_removable_partitions_ocil:questionnaire:1"> | ||
Max diff block lines reached; 1689219/1701139 bytes (99.30%) of diff not shown. |
Offset 3, 8231 lines modified | Offset 3, 8231 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-package_postfix_installed_ocil:questionnaire:1"> | ||
11 | ···· | 10 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_chown_ocil:questionnaire:1"> |
11 | ······<ocil:title>Record·Unsuccessful·Ownership·Changes·to·Files·-·chown</ocil:title> | ||
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_chown_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_gshadow_ocil:questionnaire:1"> | ||
17 | ···· | 16 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_sestatus_conf_ocil:questionnaire:1"> |
17 | ······<ocil:title>Verify·User·Who·Owns·/etc/sestatus.conf·File</ocil:title> | ||
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1"> |
23 | ······<ocil:title> | 23 | ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title> |
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_efi_grub2_cfg_ocil:questionnaire:1"> | ||
29 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-package_fapolicyd_installed_ocil:questionnaire:1"> |
29 | ······<ocil:title>Install·fapolicyd·Package</ocil:title> | ||
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-package_fapolicyd_installed_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1"> | ||
35 | ···· | 34 | ····<ocil:questionnaire·id="ocil:ssg-ensure_redhat_gpgkey_installed_ocil:questionnaire:1"> |
35 | ······<ocil:title>Ensure·Red·Hat·GPG·Key·Installed</ocil:title> | ||
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-ensure_redhat_gpgkey_installed_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 40 | ····<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 41 | ······<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title> |
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg- | 46 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1"> |
47 | ······<ocil:title> | 47 | ······<ocil:title>Disable·the·IPv6·protocol</ocil:title> |
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_noexec_removable_partitions_ocil:questionnaire:1"> | ||
53 | ···· | 52 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_etc_passwd_open_ocil:questionnaire:1"> |
53 | ······<ocil:title>Record·Events·that·Modify·User/Group·Information·via·open·syscall·-·/etc/passwd</ocil:title> | ||
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_etc_passwd_open_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-aide_build_database_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 59 | ······<ocil:title>Build·and·Test·AIDE·Database</ocil:title> |
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-aide_build_database_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nosuid_ocil:questionnaire:1"> |
65 | ······<ocil:title> | 65 | ······<ocil:title>Add·nosuid·Option·to·/home</ocil:title> |
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nosuid_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 71 | ······<ocil:title>Disable·kernel·debugfs</ocil:title> |
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-service_systemd-coredump_disabled_ocil:questionnaire:1"> | ||
77 | ···· | 76 | ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1"> |
77 | ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title> | ||
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg-s | 79 | ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_mount_nfs_ocil:questionnaire:1"> | ||
83 | ···· | 82 | ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_ocil:questionnaire:1"> |
83 | ······<ocil:title>Configure·System·to·Forward·All·Mail·From·Postmaster·to·The·Root·Account</ocil:title> | ||
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_postmaster_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-s | 88 | ····<ocil:questionnaire·id="ocil:ssg-sshd_set_maxstartups_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 89 | ······<ocil:title>Ensure·SSH·MaxStartups·is·configured</ocil:title> |
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg-s | 91 | ········<ocil:test_action_ref>ocil:ssg-sshd_set_maxstartups_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1"> | ||
95 | ···· | 94 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_ipsec_secrets_ocil:questionnaire:1"> |
95 | ······<ocil:title>Verify·Group·Who·Owns·/etc/ipsec.secrets·File</ocil:title> | ||
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_ipsec_secrets_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-audit | 100 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_chsh_ocil:questionnaire:1"> |
101 | ······<ocil:title> | 101 | ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·chsh</ocil:title> |
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg-audit | 103 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_chsh_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg- | 106 | ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_stig_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 107 | ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title> |
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_stig_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 112 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 113 | ······<ocil:title>Make·the·auditd·Configuration·Immutable</ocil:title> |
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_ | 115 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1"> | ||
119 | ···· | 118 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_ocil:questionnaire:1"> |
119 | ······<ocil:title>Enable·Kernel·Parameter·to·Ignore·Bogus·ICMP·Error·Responses·on·IPv4·Interfaces</ocil:title> | ||
120 | ······<ocil:actions> | 120 | ······<ocil:actions> |
Max diff block lines reached; 1616213/1628774 bytes (99.23%) of diff not shown. |
Offset 288, 23 lines modified | Offset 288, 23 lines modified | ||
288 | ······</cpe-lang:logical-test> | 288 | ······</cpe-lang:logical-test> |
289 | ····</cpe-lang:platform> | 289 | ····</cpe-lang:platform> |
290 | ····<cpe-lang:platform·id="package_bash"> | 290 | ····<cpe-lang:platform·id="package_bash"> |
291 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 291 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
292 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> | 292 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> |
293 | ······</cpe-lang:logical-test> | 293 | ······</cpe-lang:logical-test> |
294 | ····</cpe-lang:platform> | 294 | ····</cpe-lang:platform> |
295 | ····<cpe-lang:platform·id="os_linux_ | 295 | ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> |
296 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 296 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
297 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ | 297 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> |
298 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> | ||
299 | ······</cpe-lang:logical-test> | 298 | ······</cpe-lang:logical-test> |
300 | ····</cpe-lang:platform> | 299 | ····</cpe-lang:platform> |
301 | ····<cpe-lang:platform·id="os_linux_ | 300 | ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0"> |
302 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 301 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
303 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ | 302 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/> |
303 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> | ||
304 | ······</cpe-lang:logical-test> | 304 | ······</cpe-lang:logical-test> |
305 | ····</cpe-lang:platform> | 305 | ····</cpe-lang:platform> |
306 | ····<cpe-lang:platform·id="package_tmux"> | 306 | ····<cpe-lang:platform·id="package_tmux"> |
307 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 307 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
308 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_tmux:def:1"/> | 308 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_tmux:def:1"/> |
309 | ······</cpe-lang:logical-test> | 309 | ······</cpe-lang:logical-test> |
310 | ····</cpe-lang:platform> | 310 | ····</cpe-lang:platform> |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of | 40 | configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 312, 23 lines modified | Offset 312, 23 lines modified | ||
312 | ··········</cpe-lang:logical-test> | 312 | ··········</cpe-lang:logical-test> |
313 | ········</cpe-lang:platform> | 313 | ········</cpe-lang:platform> |
314 | ········<cpe-lang:platform·id="package_bash"> | 314 | ········<cpe-lang:platform·id="package_bash"> |
315 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 315 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
316 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> | 316 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> |
317 | ··········</cpe-lang:logical-test> | 317 | ··········</cpe-lang:logical-test> |
318 | ········</cpe-lang:platform> | 318 | ········</cpe-lang:platform> |
319 | ········<cpe-lang:platform·id="os_linux_ | 319 | ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> |
320 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 320 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
321 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ | 321 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> |
322 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> | ||
323 | ··········</cpe-lang:logical-test> | 322 | ··········</cpe-lang:logical-test> |
324 | ········</cpe-lang:platform> | 323 | ········</cpe-lang:platform> |
325 | ········<cpe-lang:platform·id="os_linux_ | 324 | ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0"> |
326 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 325 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
327 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ | 326 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/> |
327 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> | ||
328 | ··········</cpe-lang:logical-test> | 328 | ··········</cpe-lang:logical-test> |
329 | ········</cpe-lang:platform> | 329 | ········</cpe-lang:platform> |
330 | ········<cpe-lang:platform·id="not_s390x_arch"> | 330 | ········<cpe-lang:platform·id="not_s390x_arch"> |
331 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> | 331 | ··········<cpe-lang:logical-test·operator="AND"·negate="false"> |
332 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> | 332 | ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> |
333 | ··········</cpe-lang:logical-test> | 333 | ··········</cpe-lang:logical-test> |
334 | ········</cpe-lang:platform> | 334 | ········</cpe-lang:platform> |
Offset 216676, 15 lines modified | Offset 216676, 15 lines modified | ||
216676 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/> | 216676 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/> |
216677 | ············</xccdf-1.2:check> | 216677 | ············</xccdf-1.2:check> |
216678 | ··········</xccdf-1.2:Rule> | 216678 | ··········</xccdf-1.2:Rule> |
216679 | ········</xccdf-1.2:Group> | 216679 | ········</xccdf-1.2:Group> |
216680 | ······</xccdf-1.2:Group> | 216680 | ······</xccdf-1.2:Group> |
216681 | ····</xccdf-1.2:Benchmark> | 216681 | ····</xccdf-1.2:Benchmark> |
216682 | ··</ds:component> | 216682 | ··</ds:component> |
216683 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-0 | 216683 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-03-01T22:08:00"> |
216684 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 216684 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
216685 | ······<oval-def:generator> | 216685 | ······<oval-def:generator> |
216686 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 216686 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
216687 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 216687 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
216688 | ········<oval:schema_version>5.11</oval:schema_version> | 216688 | ········<oval:schema_version>5.11</oval:schema_version> |
216689 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 216689 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
216690 | ······</oval-def:generator> | 216690 | ······</oval-def:generator> |
Offset 266291, 13718 lines modified | Offset 266291, 13907 lines modified | ||
266291 | ············</oval-def:arithmetic> | 266291 | ············</oval-def:arithmetic> |
266292 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 266292 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
266293 | ··········</oval-def:arithmetic> | 266293 | ··········</oval-def:arithmetic> |
266294 | ········</oval-def:local_variable> | 266294 | ········</oval-def:local_variable> |
266295 | ······</oval-def:variables> | 266295 | ······</oval-def:variables> |
266296 | ····</oval-def:oval_definitions> | 266296 | ····</oval-def:oval_definitions> |
266297 | ··</ds:component> | 266297 | ··</ds:component> |
266298 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-0 | 266298 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
266299 | ····<ocil:ocil> | 266299 | ····<ocil:ocil> |
266300 | ······<ocil:generator> | 266300 | ······<ocil:generator> |
266301 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 266301 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
266302 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 266302 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
266303 | ········<ocil:schema_version>2.0</ocil:schema_version> | 266303 | ········<ocil:schema_version>2.0</ocil:schema_version> |
266304 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 266304 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
266305 | ······</ocil:generator> | 266305 | ······</ocil:generator> |
266306 | ······<ocil:questionnaires> | 266306 | ······<ocil:questionnaires> |
266307 | ········<ocil:questionnaire·id="ocil:ssg-accounts_po | 266307 | ········<ocil:questionnaire·id="ocil:ssg-accounts_password_set_max_life_root_ocil:questionnaire:1"> |
266308 | ··········<ocil:title> | 266308 | ··········<ocil:title>Set·Root·Account·Password·Maximum·Age</ocil:title> |
266309 | ··········<ocil:actions> | 266309 | ··········<ocil:actions> |
266310 | ············<ocil:test_action_ref>ocil:ssg-accounts_po | 266310 | ············<ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_root_action:testaction:1</ocil:test_action_ref> |
266311 | ··········</ocil:actions> | 266311 | ··········</ocil:actions> |
266312 | ········</ocil:questionnaire> | 266312 | ········</ocil:questionnaire> |
266313 | ········<ocil:questionnaire·id="ocil:ssg- | 266313 | ········<ocil:questionnaire·id="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1"> |
266314 | ··········<ocil:title> | 266314 | ··········<ocil:title>Configure·BIND·to·use·System·Crypto·Policy</ocil:title> |
266315 | ··········<ocil:actions> | 266315 | ··········<ocil:actions> |
266316 | ············<ocil:test_action_ref>ocil:ssg- | 266316 | ············<ocil:test_action_ref>ocil:ssg-configure_bind_crypto_policy_action:testaction:1</ocil:test_action_ref> |
266317 | ··········</ocil:actions> | 266317 | ··········</ocil:actions> |
266318 | ········</ocil:questionnaire> | 266318 | ········</ocil:questionnaire> |
266319 | ········<ocil:questionnaire·id="ocil:ssg- | 266319 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_user_cfg_ocil:questionnaire:1"> |
266320 | ··········<ocil:title> | 266320 | ··········<ocil:title>Verify·/boot/grub2/user.cfg·Permissions</ocil:title> |
266321 | ··········<ocil:actions> | 266321 | ··········<ocil:actions> |
266322 | ············<ocil:test_action_ref>ocil:ssg- | 266322 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_user_cfg_action:testaction:1</ocil:test_action_ref> |
266323 | ··········</ocil:actions> | 266323 | ··········</ocil:actions> |
266324 | ········</ocil:questionnaire> | 266324 | ········</ocil:questionnaire> |
266325 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_modules_disabled_ocil:questionnaire:1"> | ||
266326 | ········ | 266325 | ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_enforce_root_ocil:questionnaire:1"> |
266326 | ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Enforce·for·root·User</ocil:title> | ||
266327 | ··········<ocil:actions> | 266327 | ··········<ocil:actions> |
266328 | ············<ocil:test_action_ref>ocil:ssg- | 266328 | ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_enforce_root_action:testaction:1</ocil:test_action_ref> |
266329 | ··········</ocil:actions> | 266329 | ··········</ocil:actions> |
266330 | ········</ocil:questionnaire> | 266330 | ········</ocil:questionnaire> |
266331 | ········<ocil:questionnaire·id="ocil:ssg- | 266331 | ········<ocil:questionnaire·id="ocil:ssg-gid_passwd_group_same_ocil:questionnaire:1"> |
266332 | ··········<ocil:title>A | 266332 | ··········<ocil:title>All·GIDs·referenced·in·/etc/passwd·must·be·defined·in·/etc/group</ocil:title> |
266333 | ··········<ocil:actions> | 266333 | ··········<ocil:actions> |
266334 | ············<ocil:test_action_ref>ocil:ssg- | 266334 | ············<ocil:test_action_ref>ocil:ssg-gid_passwd_group_same_action:testaction:1</ocil:test_action_ref> |
266335 | ··········</ocil:actions> | 266335 | ··········</ocil:actions> |
266336 | ········</ocil:questionnaire> | 266336 | ········</ocil:questionnaire> |
266337 | ········<ocil:questionnaire·id="ocil:ssg- | 266337 | ········<ocil:questionnaire·id="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1"> |
266338 | ··········<ocil:title> | 266338 | ··········<ocil:title>Set·SSH·MaxSessions·limit</ocil:title> |
266339 | ··········<ocil:actions> | 266339 | ··········<ocil:actions> |
266340 | ············<ocil:test_action_ref>ocil:ssg- | 266340 | ············<ocil:test_action_ref>ocil:ssg-sshd_set_max_sessions_action:testaction:1</ocil:test_action_ref> |
266341 | ··········</ocil:actions> | 266341 | ··········</ocil:actions> |
266342 | ········</ocil:questionnaire> | 266342 | ········</ocil:questionnaire> |
266343 | ········<ocil:questionnaire·id="ocil:ssg- | 266343 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1"> |
266344 | ··········<ocil:title> | 266344 | ··········<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title> |
266345 | ··········<ocil:actions> | 266345 | ··········<ocil:actions> |
266346 | ············<ocil:test_action_ref>ocil:ssg- | 266346 | ············<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref> |
266347 | ··········</ocil:actions> | 266347 | ··········</ocil:actions> |
266348 | ········</ocil:questionnaire> | 266348 | ········</ocil:questionnaire> |
266349 | ········<ocil:questionnaire·id="ocil:ssg- | 266349 | ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_login_banner_text_ocil:questionnaire:1"> |
266350 | ··········<ocil:title> | 266350 | ··········<ocil:title>Set·the·GNOME3·Login·Warning·Banner·Text</ocil:title> |
266351 | ··········<ocil:actions> | 266351 | ··········<ocil:actions> |
Max diff block lines reached; 2240747/2252992 bytes (99.46%) of diff not shown. |
Offset 3, 13709 lines modified | Offset 3, 13898 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-accounts_po | 10 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_max_life_root_ocil:questionnaire:1"> |
11 | ······<ocil:title> | 11 | ······<ocil:title>Set·Root·Account·Password·Maximum·Age</ocil:title> |
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg-accounts_po | 13 | ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_root_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg- | 16 | ····<ocil:questionnaire·id="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1"> |
17 | ······<ocil:title> | 17 | ······<ocil:title>Configure·BIND·to·use·System·Crypto·Policy</ocil:title> |
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-configure_bind_crypto_policy_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_user_cfg_ocil:questionnaire:1"> |
23 | ······<ocil:title> | 23 | ······<ocil:title>Verify·/boot/grub2/user.cfg·Permissions</ocil:title> |
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_user_cfg_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_modules_disabled_ocil:questionnaire:1"> | ||
29 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_enforce_root_ocil:questionnaire:1"> |
29 | ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Enforce·for·root·User</ocil:title> | ||
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_enforce_root_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-gid_passwd_group_same_ocil:questionnaire:1"> |
35 | ······<ocil:title>A | 35 | ······<ocil:title>All·GIDs·referenced·in·/etc/passwd·must·be·defined·in·/etc/group</ocil:title> |
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-gid_passwd_group_same_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 40 | ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 41 | ······<ocil:title>Set·SSH·MaxSessions·limit</ocil:title> |
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_sessions_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg- | 46 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1"> |
47 | ······<ocil:title> | 47 | ······<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title> |
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 52 | ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_login_banner_text_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 53 | ······<ocil:title>Set·the·GNOME3·Login·Warning·Banner·Text</ocil:title> |
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_login_banner_text_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_passwd_ocil:questionnaire:1"> | ||
59 | ···· | 58 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_ocil:questionnaire:1"> |
59 | ······<ocil:title>Configure·Auto·Configuration·on·All·IPv6·Interfaces</ocil:title> | ||
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_fortify_source_ocil:questionnaire:1"> |
65 | ······<ocil:title> | 65 | ······<ocil:title>Harden·common·str/mem·functions·against·buffer·overflows</ocil:title> |
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_fortify_source_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_credentials_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 71 | ······<ocil:title>Enable·checks·on·credential·management</ocil:title> |
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_credentials_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg- | 76 | ····<ocil:questionnaire·id="ocil:ssg-audit_modify_failed_ppc64le_ocil:questionnaire:1"> |
77 | ······<ocil:title> | 77 | ······<ocil:title>Configure·auditing·of·unsuccessful·file·modifications·(ppc64le)</ocil:title> |
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-audit_modify_failed_ppc64le_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg- | 82 | ····<ocil:questionnaire·id="ocil:ssg-audit_module_load_ppc64le_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 83 | ······<ocil:title>Configure·auditing·of·loading·and·unloading·of·kernel·modules·(ppc64le)</ocil:title> |
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-audit_module_load_ppc64le_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg- | 88 | ····<ocil:questionnaire·id="ocil:ssg-enable_fips_mode_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 89 | ······<ocil:title>Enable·FIPS·Mode</ocil:title> |
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-enable_fips_mode_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg- | 94 | ····<ocil:questionnaire·id="ocil:ssg-audit_owner_change_failed_ppc64le_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 95 | ······<ocil:title>Configure·auditing·of·unsuccessful·ownership·changes·(ppc64le)</ocil:title> |
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-audit_owner_change_failed_ppc64le_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_network_scripts_ocil:questionnaire:1"> | ||
101 | ···· | 100 | ····<ocil:questionnaire·id="ocil:ssg-package_usbguard_installed_ocil:questionnaire:1"> |
101 | ······<ocil:title>Install·usbguard·Package</ocil:title> | ||
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-package_usbguard_installed_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ | 106 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_syn_cookies_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 107 | ······<ocil:title>Enable·TCP/IP·syncookie·support</ocil:title> |
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_ | 109 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_syn_cookies_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-tftp_uses_secure_mode_systemd_ocil:questionnaire:1"> | ||
113 | ···· | 112 | ····<ocil:questionnaire·id="ocil:ssg-network_nmcli_permissions_ocil:questionnaire:1"> |
113 | ······<ocil:title>Prevent·non-Privileged·Users·from·Modifying·Network·Interfaces·using·nmcli</ocil:title> | ||
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-network_nmcli_permissions_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1"> | ||
119 | ···· | 118 | ····<ocil:questionnaire·id="ocil:ssg-file_permission_user_init_files_root_ocil:questionnaire:1"> |
119 | ······<ocil:title>Ensure·All·User·Initialization·Files·Have·Mode·0740·Or·Less·Permissive</ocil:title> | ||
120 | ······<ocil:actions> | 120 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg- | 121 | ········<ocil:test_action_ref>ocil:ssg-file_permission_user_init_files_root_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 122 | ······</ocil:actions> |
123 | ····</ocil:questionnaire> | 123 | ····</ocil:questionnaire> |
124 | ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1"> | ||
Max diff block lines reached; 2143706/2156772 bytes (99.39%) of diff not shown. |
Offset 279, 23 lines modified | Offset 279, 23 lines modified | ||
279 | ······</cpe-lang:logical-test> | 279 | ······</cpe-lang:logical-test> |
280 | ····</cpe-lang:platform> | 280 | ····</cpe-lang:platform> |
281 | ····<cpe-lang:platform·id="package_bash"> | 281 | ····<cpe-lang:platform·id="package_bash"> |
282 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 282 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
283 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> | 283 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/> |
284 | ······</cpe-lang:logical-test> | 284 | ······</cpe-lang:logical-test> |
285 | ····</cpe-lang:platform> | 285 | ····</cpe-lang:platform> |
286 | ····<cpe-lang:platform·id="os_linux_ | 286 | ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> |
287 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 287 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
288 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ | 288 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> |
289 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> | ||
290 | ······</cpe-lang:logical-test> | 289 | ······</cpe-lang:logical-test> |
291 | ····</cpe-lang:platform> | 290 | ····</cpe-lang:platform> |
292 | ····<cpe-lang:platform·id="os_linux_ | 291 | ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0"> |
293 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 292 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
294 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ | 293 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/> |
294 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> | ||
295 | ······</cpe-lang:logical-test> | 295 | ······</cpe-lang:logical-test> |
296 | ····</cpe-lang:platform> | 296 | ····</cpe-lang:platform> |
297 | ····<cpe-lang:platform·id="not_s390x_arch"> | 297 | ····<cpe-lang:platform·id="not_s390x_arch"> |
298 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> | 298 | ······<cpe-lang:logical-test·operator="AND"·negate="false"> |
299 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> | 299 | ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> |
300 | ······</cpe-lang:logical-test> | 300 | ······</cpe-lang:logical-test> |
301 | ····</cpe-lang:platform> | 301 | ····</cpe-lang:platform> |
Offset 19, 15 lines modified | Offset 19, 15 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0"> | 32 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0"> |
33 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title> | 33 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title> |
Offset 71, 15 lines modified | Offset 71, 15 lines modified | ||
71 | ······</cpe-dict:cpe-item> | 71 | ······</cpe-dict:cpe-item> |
72 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.9"> | 72 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.9"> |
73 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.9</cpe-dict:title> | 73 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.9</cpe-dict:title> |
74 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8_9:def:1</cpe-dict:check> | 74 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8_9:def:1</cpe-dict:check> |
75 | ······</cpe-dict:cpe-item> | 75 | ······</cpe-dict:cpe-item> |
76 | ····</cpe-dict:cpe-list> | 76 | ····</cpe-dict:cpe-list> |
77 | ··</ds:component> | 77 | ··</ds:component> |
78 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-0 | 78 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
79 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 79 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
80 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 80 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
81 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title> | 81 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title> |
82 | ······<xccdf-1.2:description> | 82 | ······<xccdf-1.2:description> |
83 | ········This·guide·presents·a·catalog·of·security-relevant | 83 | ········This·guide·presents·a·catalog·of·security-relevant |
84 | configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of | 84 | configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of |
85 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 85 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 317526, 15 lines modified | Offset 317526, 15 lines modified | ||
317526 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/> | 317526 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/> |
317527 | ············</xccdf-1.2:check> | 317527 | ············</xccdf-1.2:check> |
317528 | ··········</xccdf-1.2:Rule> | 317528 | ··········</xccdf-1.2:Rule> |
317529 | ········</xccdf-1.2:Group> | 317529 | ········</xccdf-1.2:Group> |
317530 | ······</xccdf-1.2:Group> | 317530 | ······</xccdf-1.2:Group> |
317531 | ····</xccdf-1.2:Benchmark> | 317531 | ····</xccdf-1.2:Benchmark> |
317532 | ··</ds:component> | 317532 | ··</ds:component> |
317533 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-0 | 317533 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-03-01T22:08:00"> |
317534 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 317534 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
317535 | ······<oval-def:generator> | 317535 | ······<oval-def:generator> |
317536 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 317536 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
317537 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 317537 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
317538 | ········<oval:schema_version>5.11</oval:schema_version> | 317538 | ········<oval:schema_version>5.11</oval:schema_version> |
317539 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 317539 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
317540 | ······</oval-def:generator> | 317540 | ······</oval-def:generator> |
Offset 385018, 18135 lines modified | Offset 385018, 18135 lines modified | ||
385018 | ············</oval-def:arithmetic> | 385018 | ············</oval-def:arithmetic> |
385019 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/> | 385019 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/> |
385020 | ··········</oval-def:arithmetic> | 385020 | ··········</oval-def:arithmetic> |
385021 | ········</oval-def:local_variable> | 385021 | ········</oval-def:local_variable> |
385022 | ······</oval-def:variables> | 385022 | ······</oval-def:variables> |
385023 | ····</oval-def:oval_definitions> | 385023 | ····</oval-def:oval_definitions> |
385024 | ··</ds:component> | 385024 | ··</ds:component> |
385025 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-0 | 385025 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
385026 | ····<ocil:ocil> | 385026 | ····<ocil:ocil> |
385027 | ······<ocil:generator> | 385027 | ······<ocil:generator> |
385028 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 385028 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
385029 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 385029 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
385030 | ········<ocil:schema_version>2.0</ocil:schema_version> | 385030 | ········<ocil:schema_version>2.0</ocil:schema_version> |
385031 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 385031 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
385032 | ······</ocil:generator> | 385032 | ······</ocil:generator> |
385033 | ······<ocil:questionnaires> | 385033 | ······<ocil:questionnaires> |
385034 | ········<ocil:questionnaire·id="ocil:ssg- | 385034 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1"> |
385035 | ··········<ocil:title> | 385035 | ··········<ocil:title>Verify·User·Who·Owns·Backup·passwd·File</ocil:title> |
385036 | ··········<ocil:actions> | 385036 | ··········<ocil:actions> |
385037 | ············<ocil:test_action_ref>ocil:ssg- | 385037 | ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref> |
385038 | ··········</ocil:actions> | 385038 | ··········</ocil:actions> |
385039 | ········</ocil:questionnaire> | 385039 | ········</ocil:questionnaire> |
385040 | ········<ocil:questionnaire·id="ocil:ssg- | 385040 | ········<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1"> |
385041 | ··········<ocil:title> | 385041 | ··········<ocil:title>Uninstall·rsh-server·Package</ocil:title> |
385042 | ··········<ocil:actions> | 385042 | ··········<ocil:actions> |
385043 | ············<ocil:test_action_ref>ocil:ssg- | 385043 | ············<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref> |
385044 | ··········</ocil:actions> | 385044 | ··········</ocil:actions> |
385045 | ········</ocil:questionnaire> | 385045 | ········</ocil:questionnaire> |
385046 | ········<ocil:questionnaire·id="ocil:ssg- | 385046 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_ocil:questionnaire:1"> |
385047 | ··········<ocil:title> | 385047 | ··········<ocil:title>Emulate·Privileged·Access·Never·(PAN)</ocil:title> |
385048 | ··········<ocil:actions> | 385048 | ··········<ocil:actions> |
385049 | ············<ocil:test_action_ref>ocil:ssg- | 385049 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_action:testaction:1</ocil:test_action_ref> |
385050 | ··········</ocil:actions> | 385050 | ··········</ocil:actions> |
385051 | ········</ocil:questionnaire> | 385051 | ········</ocil:questionnaire> |
385052 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 385052 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_login_uids_ocil:questionnaire:1"> |
385053 | ··········<ocil:title> | 385053 | ··········<ocil:title>Configure·immutable·Audit·login·UIDs</ocil:title> |
385054 | ··········<ocil:actions> | 385054 | ··········<ocil:actions> |
385055 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_ | 385055 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_login_uids_action:testaction:1</ocil:test_action_ref> |
385056 | ··········</ocil:actions> | 385056 | ··········</ocil:actions> |
385057 | ········</ocil:questionnaire> | 385057 | ········</ocil:questionnaire> |
385058 | ········<ocil:questionnaire·id="ocil:ssg- | 385058 | ········<ocil:questionnaire·id="ocil:ssg-selinux_all_devicefiles_labeled_ocil:questionnaire:1"> |
385059 | ··········<ocil:title> | 385059 | ··········<ocil:title>Ensure·No·Device·Files·are·Unlabeled·by·SELinux</ocil:title> |
385060 | ··········<ocil:actions> | 385060 | ··········<ocil:actions> |
385061 | ············<ocil:test_action_ref>ocil:ssg- | 385061 | ············<ocil:test_action_ref>ocil:ssg-selinux_all_devicefiles_labeled_action:testaction:1</ocil:test_action_ref> |
385062 | ··········</ocil:actions> | 385062 | ··········</ocil:actions> |
385063 | ········</ocil:questionnaire> | 385063 | ········</ocil:questionnaire> |
385064 | ········<ocil:questionnaire·id="ocil:ssg-a | 385064 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1"> |
385065 | ··········<ocil:title>Ensure· | 385065 | ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title> |
385066 | ··········<ocil:actions> | 385066 | ··········<ocil:actions> |
385067 | ············<ocil:test_action_ref>ocil:ssg-a | 385067 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref> |
385068 | ··········</ocil:actions> | 385068 | ··········</ocil:actions> |
385069 | ········</ocil:questionnaire> | 385069 | ········</ocil:questionnaire> |
385070 | ········<ocil:questionnaire·id="ocil:ssg- | 385070 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"> |
385071 | ··········<ocil:title> | 385071 | ··········<ocil:title>Configure·audit·according·to·OSPP·requirements</ocil:title> |
385072 | ··········<ocil:actions> | 385072 | ··········<ocil:actions> |
385073 | ············<ocil:test_action_ref>ocil:ssg- | 385073 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_for_ospp_action:testaction:1</ocil:test_action_ref> |
385074 | ··········</ocil:actions> | 385074 | ··········</ocil:actions> |
385075 | ········</ocil:questionnaire> | 385075 | ········</ocil:questionnaire> |
385076 | ········<ocil:questionnaire·id="ocil:ssg- | 385076 | ········<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1"> |
385077 | ··········<ocil:title> | 385077 | ··········<ocil:title>The·Chrony·package·is·installed</ocil:title> |
385078 | ··········<ocil:actions> | 385078 | ··········<ocil:actions> |
385079 | ············<ocil:test_action_ref>ocil:ssg- | 385079 | ············<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref> |
385080 | ··········</ocil:actions> | 385080 | ··········</ocil:actions> |
385081 | ········</ocil:questionnaire> | 385081 | ········</ocil:questionnaire> |
385082 | ········<ocil:questionnaire·id="ocil:ssg- | 385082 | ········<ocil:questionnaire·id="ocil:ssg-sebool_cobbler_can_network_connect_ocil:questionnaire:1"> |
385083 | ··········<ocil:title> | 385083 | ··········<ocil:title>Disable·the·cobbler_can_network_connect·SELinux·Boolean</ocil:title> |
385084 | ··········<ocil:actions> | 385084 | ··········<ocil:actions> |
385085 | ············<ocil:test_action_ref>ocil:ssg- | 385085 | ············<ocil:test_action_ref>ocil:ssg-sebool_cobbler_can_network_connect_action:testaction:1</ocil:test_action_ref> |
385086 | ··········</ocil:actions> | 385086 | ··········</ocil:actions> |
385087 | ········</ocil:questionnaire> | 385087 | ········</ocil:questionnaire> |
385088 | ········<ocil:questionnaire·id="ocil:ssg-s | 385088 | ········<ocil:questionnaire·id="ocil:ssg-package_scap-security-guide_installed_ocil:questionnaire:1"> |
385089 | ··········<ocil:title> | 385089 | ··········<ocil:title>Install·scap-security-guide·Package</ocil:title> |
385090 | ··········<ocil:actions> | 385090 | ··········<ocil:actions> |
385091 | ············<ocil:test_action_ref>ocil:ssg-s | 385091 | ············<ocil:test_action_ref>ocil:ssg-package_scap-security-guide_installed_action:testaction:1</ocil:test_action_ref> |
385092 | ··········</ocil:actions> | 385092 | ··········</ocil:actions> |
385093 | ········</ocil:questionnaire> | 385093 | ········</ocil:questionnaire> |
385094 | ········<ocil:questionnaire·id="ocil:ssg- | 385094 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1"> |
385095 | ··········<ocil:title>Verify· | 385095 | ··········<ocil:title>Verify·Owner·on·crontab</ocil:title> |
385096 | ··········<ocil:actions> | 385096 | ··········<ocil:actions> |
Max diff block lines reached; 3568422/3580580 bytes (99.66%) of diff not shown. |
Offset 3, 18126 lines modified | Offset 3, 18126 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg- | 10 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1"> |
11 | ······<ocil:title> | 11 | ······<ocil:title>Verify·User·Who·Owns·Backup·passwd·File</ocil:title> |
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg- | 16 | ····<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1"> |
17 | ······<ocil:title> | 17 | ······<ocil:title>Uninstall·rsh-server·Package</ocil:title> |
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_ocil:questionnaire:1"> |
23 | ······<ocil:title> | 23 | ······<ocil:title>Emulate·Privileged·Access·Never·(PAN)</ocil:title> |
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 28 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_login_uids_ocil:questionnaire:1"> |
29 | ······<ocil:title> | 29 | ······<ocil:title>Configure·immutable·Audit·login·UIDs</ocil:title> |
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_ | 31 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_login_uids_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-selinux_all_devicefiles_labeled_ocil:questionnaire:1"> |
35 | ······<ocil:title> | 35 | ······<ocil:title>Ensure·No·Device·Files·are·Unlabeled·by·SELinux</ocil:title> |
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-selinux_all_devicefiles_labeled_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-a | 40 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1"> |
41 | ······<ocil:title>Ensure· | 41 | ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title> |
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg-a | 43 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg- | 46 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"> |
47 | ······<ocil:title> | 47 | ······<ocil:title>Configure·audit·according·to·OSPP·requirements</ocil:title> |
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_for_ospp_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 52 | ····<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 53 | ······<ocil:title>The·Chrony·package·is·installed</ocil:title> |
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-sebool_cobbler_can_network_connect_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 59 | ······<ocil:title>Disable·the·cobbler_can_network_connect·SELinux·Boolean</ocil:title> |
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-sebool_cobbler_can_network_connect_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-s | 64 | ····<ocil:questionnaire·id="ocil:ssg-package_scap-security-guide_installed_ocil:questionnaire:1"> |
65 | ······<ocil:title> | 65 | ······<ocil:title>Install·scap-security-guide·Package</ocil:title> |
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg-s | 67 | ········<ocil:test_action_ref>ocil:ssg-package_scap-security-guide_installed_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1"> |
71 | ······<ocil:title>Verify· | 71 | ······<ocil:title>Verify·Owner·on·crontab</ocil:title> |
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_ocil:questionnaire:1"> | ||
77 | ···· | 76 | ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1"> |
77 | ······<ocil:title>Set·Lockout·Time·for·Failed·Password·Attempts</ocil:title> | ||
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_unlock_time_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-file_ | 82 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_grub2_cfg_ocil:questionnaire:1"> |
83 | ······<ocil:title>Verify· | 83 | ······<ocil:title>Verify·/boot/grub2/grub.cfg·Permissions</ocil:title> |
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg-file_ | 85 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_grub2_cfg_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg- | 88 | ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_private_key_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 89 | ······<ocil:title>Verify·Group·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title> |
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_private_key_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg- | 94 | ····<ocil:questionnaire·id="ocil:ssg-dir_perms_world_writable_system_owned_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 95 | ······<ocil:title>Ensure·All·World-Writable·Directories·Are·Owned·by·a·System·Account</ocil:title> |
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_system_owned_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-file_ | 100 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_efi_grub2_cfg_ocil:questionnaire:1"> |
101 | ······<ocil:title>Verify· | 101 | ······<ocil:title>Verify·the·UEFI·Boot·Loader·grub.cfg·User·Ownership</ocil:title> |
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg-file_ | 103 | ········<ocil:test_action_ref>ocil:ssg-file_owner_efi_grub2_cfg_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ | 106 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_httpd_server_conf_d_files_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 107 | ······<ocil:title>Set·Permissions·on·All·Configuration·Files·Inside·/etc/httpd/conf.d/</ocil:title> |
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_ | 109 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_httpd_server_conf_d_files_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-directory_groupowner_etc_selinux_ocil:questionnaire:1"> | ||
113 | ···· | 112 | ····<ocil:questionnaire·id="ocil:ssg-package_avahi-autoipd_removed_ocil:questionnaire:1"> |
113 | ······<ocil:title>Uninstall·avahi-autoipd·Server·Package</ocil:title> | ||
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-package_avahi-autoipd_removed_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-se | 118 | ····<ocil:questionnaire·id="ocil:ssg-securetty_root_login_console_only_ocil:questionnaire:1"> |
119 | ······<ocil:title> | 119 | ······<ocil:title>Restrict·Virtual·Console·Root·Logins</ocil:title> |
120 | ······<ocil:actions> | 120 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg-se | 121 | ········<ocil:test_action_ref>ocil:ssg-securetty_root_login_console_only_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 122 | ······</ocil:actions> |
123 | ····</ocil:questionnaire> | 123 | ····</ocil:questionnaire> |
124 | ····<ocil:questionnaire·id="ocil:ssg- | 124 | ····<ocil:questionnaire·id="ocil:ssg-file_audit_tools_permissions_ocil:questionnaire:1"> |
125 | ······<ocil:title> | 125 | ······<ocil:title>Audit·Tools·Must·Have·a·Mode·of·0755·or·Less·Permissive</ocil:title> |
126 | ······<ocil:actions> | 126 | ······<ocil:actions> |
127 | ········<ocil:test_action_ref>ocil:ssg- | 127 | ········<ocil:test_action_ref>ocil:ssg-file_audit_tools_permissions_action:testaction:1</ocil:test_action_ref> |
Max diff block lines reached; 3419454/3432546 bytes (99.62%) of diff not shown. |
Offset 19, 23 lines modified | Offset 19, 23 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ····</cpe-dict:cpe-list> | 32 | ····</cpe-dict:cpe-list> |
33 | ··</ds:component> | 33 | ··</ds:component> |
34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-0 | 34 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 35 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 36 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title> | 37 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title> |
38 | ······<xccdf-1.2:description> | 38 | ······<xccdf-1.2:description> |
39 | ········This·guide·presents·a·catalog·of·security-relevant | 39 | ········This·guide·presents·a·catalog·of·security-relevant |
40 | configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of | 40 | configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of |
41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 41 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 310419, 15 lines modified | Offset 310419, 15 lines modified | ||
310419 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/> | 310419 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/> |
310420 | ············</xccdf-1.2:check> | 310420 | ············</xccdf-1.2:check> |
310421 | ··········</xccdf-1.2:Rule> | 310421 | ··········</xccdf-1.2:Rule> |
310422 | ········</xccdf-1.2:Group> | 310422 | ········</xccdf-1.2:Group> |
310423 | ······</xccdf-1.2:Group> | 310423 | ······</xccdf-1.2:Group> |
310424 | ····</xccdf-1.2:Benchmark> | 310424 | ····</xccdf-1.2:Benchmark> |
310425 | ··</ds:component> | 310425 | ··</ds:component> |
310426 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-0 | 310426 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-03-01T22:08:00"> |
310427 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 310427 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
310428 | ······<oval-def:generator> | 310428 | ······<oval-def:generator> |
310429 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 310429 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
310430 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 310430 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
310431 | ········<oval:schema_version>5.11</oval:schema_version> | 310431 | ········<oval:schema_version>5.11</oval:schema_version> |
310432 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 310432 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
310433 | ······</oval-def:generator> | 310433 | ······</oval-def:generator> |
Offset 377198, 20441 lines modified | Offset 377198, 20442 lines modified | ||
377198 | ············</oval-def:arithmetic> | 377198 | ············</oval-def:arithmetic> |
377199 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 377199 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
377200 | ··········</oval-def:arithmetic> | 377200 | ··········</oval-def:arithmetic> |
377201 | ········</oval-def:local_variable> | 377201 | ········</oval-def:local_variable> |
377202 | ······</oval-def:variables> | 377202 | ······</oval-def:variables> |
377203 | ····</oval-def:oval_definitions> | 377203 | ····</oval-def:oval_definitions> |
377204 | ··</ds:component> | 377204 | ··</ds:component> |
377205 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-0 | 377205 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
377206 | ····<ocil:ocil> | 377206 | ····<ocil:ocil> |
377207 | ······<ocil:generator> | 377207 | ······<ocil:generator> |
377208 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 377208 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
377209 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 377209 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
377210 | ········<ocil:schema_version>2.0</ocil:schema_version> | 377210 | ········<ocil:schema_version>2.0</ocil:schema_version> |
377211 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 377211 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
377212 | ······</ocil:generator> | 377212 | ······</ocil:generator> |
377213 | ······<ocil:questionnaires> | 377213 | ······<ocil:questionnaires> |
377214 | ········<ocil:questionnaire·id="ocil:ssg-file_ | 377214 | ········<ocil:questionnaire·id="ocil:ssg-file_audit_tools_group_ownership_ocil:questionnaire:1"> |
377215 | ··········<ocil:title> | 377215 | ··········<ocil:title>Audit·Tools·Must·Be·Group-owned·by·Root</ocil:title> |
377216 | ··········<ocil:actions> | 377216 | ··········<ocil:actions> |
377217 | ············<ocil:test_action_ref>ocil:ssg-file_ | 377217 | ············<ocil:test_action_ref>ocil:ssg-file_audit_tools_group_ownership_action:testaction:1</ocil:test_action_ref> |
377218 | ··········</ocil:actions> | 377218 | ··········</ocil:actions> |
377219 | ········</ocil:questionnaire> | 377219 | ········</ocil:questionnaire> |
377220 | ········<ocil:questionnaire·id="ocil:ssg-sebool_ | 377220 | ········<ocil:questionnaire·id="ocil:ssg-sebool_httpd_ssi_exec_ocil:questionnaire:1"> |
377221 | ··········<ocil:title>Disable·the· | 377221 | ··········<ocil:title>Disable·the·httpd_ssi_exec·SELinux·Boolean</ocil:title> |
377222 | ··········<ocil:actions> | 377222 | ··········<ocil:actions> |
377223 | ············<ocil:test_action_ref>ocil:ssg-sebool_ | 377223 | ············<ocil:test_action_ref>ocil:ssg-sebool_httpd_ssi_exec_action:testaction:1</ocil:test_action_ref> |
377224 | ··········</ocil:actions> | 377224 | ··········</ocil:actions> |
377225 | ········</ocil:questionnaire> | 377225 | ········</ocil:questionnaire> |
377226 | ········<ocil:questionnaire·id="ocil:ssg-se | 377226 | ········<ocil:questionnaire·id="ocil:ssg-sebool_exim_read_user_files_ocil:questionnaire:1"> |
377227 | ··········<ocil:title> | 377227 | ··········<ocil:title>Disable·the·exim_read_user_files·SELinux·Boolean</ocil:title> |
377228 | ··········<ocil:actions> | 377228 | ··········<ocil:actions> |
377229 | ············<ocil:test_action_ref>ocil:ssg-se | 377229 | ············<ocil:test_action_ref>ocil:ssg-sebool_exim_read_user_files_action:testaction:1</ocil:test_action_ref> |
377230 | ··········</ocil:actions> | 377230 | ··········</ocil:actions> |
377231 | ········</ocil:questionnaire> | 377231 | ········</ocil:questionnaire> |
377232 | ········<ocil:questionnaire·id="ocil:ssg- | 377232 | ········<ocil:questionnaire·id="ocil:ssg-file_cron_allow_exists_ocil:questionnaire:1"> |
377233 | ··········<ocil:title> | 377233 | ··········<ocil:title>Ensure·that·/etc/cron.allow·exists</ocil:title> |
377234 | ··········<ocil:actions> | 377234 | ··········<ocil:actions> |
377235 | ············<ocil:test_action_ref>ocil:ssg- | 377235 | ············<ocil:test_action_ref>ocil:ssg-file_cron_allow_exists_action:testaction:1</ocil:test_action_ref> |
377236 | ··········</ocil:actions> | 377236 | ··········</ocil:actions> |
377237 | ········</ocil:questionnaire> | 377237 | ········</ocil:questionnaire> |
377238 | ········<ocil:questionnaire·id="ocil:ssg- | 377238 | ········<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1"> |
377239 | ··········<ocil:title>En | 377239 | ··········<ocil:title>Enable·cron·Service</ocil:title> |
377240 | ··········<ocil:actions> | 377240 | ··········<ocil:actions> |
377241 | ············<ocil:test_action_ref>ocil:ssg- | 377241 | ············<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref> |
377242 | ··········</ocil:actions> | 377242 | ··········</ocil:actions> |
377243 | ········</ocil:questionnaire> | 377243 | ········</ocil:questionnaire> |
377244 | ········<ocil:questionnaire·id="ocil:ssg- | 377244 | ········<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1"> |
377245 | ··········<ocil:title>Disable· | 377245 | ··········<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title> |
377246 | ··········<ocil:actions> | 377246 | ··········<ocil:actions> |
377247 | ············<ocil:test_action_ref>ocil:ssg- | 377247 | ············<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref> |
377248 | ··········</ocil:actions> | 377248 | ··········</ocil:actions> |
377249 | ········</ocil:questionnaire> | 377249 | ········</ocil:questionnaire> |
377250 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_syn_cookies_ocil:questionnaire:1"> | ||
377251 | ········ | 377250 | ········<ocil:questionnaire·id="ocil:ssg-audit_modify_failed_ppc64le_ocil:questionnaire:1"> |
377251 | ··········<ocil:title>Configure·auditing·of·unsuccessful·file·modifications·(ppc64le)</ocil:title> | ||
377252 | ··········<ocil:actions> | 377252 | ··········<ocil:actions> |
377253 | ············<ocil:test_action_ref>ocil:ssg- | 377253 | ············<ocil:test_action_ref>ocil:ssg-audit_modify_failed_ppc64le_action:testaction:1</ocil:test_action_ref> |
377254 | ··········</ocil:actions> | 377254 | ··········</ocil:actions> |
377255 | ········</ocil:questionnaire> | 377255 | ········</ocil:questionnaire> |
377256 | ········<ocil:questionnaire·id="ocil:ssg-s | 377256 | ········<ocil:questionnaire·id="ocil:ssg-sebool_httpd_can_network_relay_ocil:questionnaire:1"> |
377257 | ··········<ocil:title> | 377257 | ··········<ocil:title>Disable·the·httpd_can_network_relay·SELinux·Boolean</ocil:title> |
377258 | ··········<ocil:actions> | 377258 | ··········<ocil:actions> |
377259 | ············<ocil:test_action_ref>ocil:ssg-s | 377259 | ············<ocil:test_action_ref>ocil:ssg-sebool_httpd_can_network_relay_action:testaction:1</ocil:test_action_ref> |
377260 | ··········</ocil:actions> | 377260 | ··········</ocil:actions> |
377261 | ········</ocil:questionnaire> | 377261 | ········</ocil:questionnaire> |
377262 | ········<ocil:questionnaire·id="ocil:ssg- | 377262 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_issue_net_ocil:questionnaire:1"> |
377263 | ··········<ocil:title> | 377263 | ··········<ocil:title>Verify·Group·Ownership·of·System·Login·Banner·for·Remote·Connections</ocil:title> |
377264 | ··········<ocil:actions> | 377264 | ··········<ocil:actions> |
377265 | ············<ocil:test_action_ref>ocil:ssg- | 377265 | ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_net_action:testaction:1</ocil:test_action_ref> |
377266 | ··········</ocil:actions> | 377266 | ··········</ocil:actions> |
377267 | ········</ocil:questionnaire> | 377267 | ········</ocil:questionnaire> |
377268 | ········<ocil:questionnaire·id="ocil:ssg- | 377268 | ········<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_binaries_ocil:questionnaire:1"> |
377269 | ··········<ocil:title> | 377269 | ··········<ocil:title>Verify·that·audit·tools·are·owned·by·root</ocil:title> |
377270 | ··········<ocil:actions> | 377270 | ··········<ocil:actions> |
377271 | ············<ocil:test_action_ref>ocil:ssg- | 377271 | ············<ocil:test_action_ref>ocil:ssg-file_ownership_audit_binaries_action:testaction:1</ocil:test_action_ref> |
377272 | ··········</ocil:actions> | 377272 | ··········</ocil:actions> |
377273 | ········</ocil:questionnaire> | 377273 | ········</ocil:questionnaire> |
377274 | ········<ocil:questionnaire·id="ocil:ssg- | 377274 | ········<ocil:questionnaire·id="ocil:ssg-package_geolite2-city_removed_ocil:questionnaire:1"> |
377275 | ··········<ocil:title> | 377275 | ··········<ocil:title>Uninstall·geolite2-city·Package</ocil:title> |
377276 | ··········<ocil:actions> | 377276 | ··········<ocil:actions> |
377277 | ············<ocil:test_action_ref>ocil:ssg- | 377277 | ············<ocil:test_action_ref>ocil:ssg-package_geolite2-city_removed_action:testaction:1</ocil:test_action_ref> |
377278 | ··········</ocil:actions> | 377278 | ··········</ocil:actions> |
377279 | ········</ocil:questionnaire> | 377279 | ········</ocil:questionnaire> |
377280 | ········<ocil:questionnaire·id="ocil:ssg- | 377280 | ········<ocil:questionnaire·id="ocil:ssg-dnf-automatic_security_updates_only_ocil:questionnaire:1"> |
377281 | ··········<ocil:title> | 377281 | ··········<ocil:title>Configure·dnf-automatic·to·Install·Only·Security·Updates</ocil:title> |
377282 | ··········<ocil:actions> | 377282 | ··········<ocil:actions> |
377283 | ············<ocil:test_action_ref>ocil:ssg- | 377283 | ············<ocil:test_action_ref>ocil:ssg-dnf-automatic_security_updates_only_action:testaction:1</ocil:test_action_ref> |
Max diff block lines reached; 3437985/3450269 bytes (99.64%) of diff not shown. |
Offset 3, 20432 lines modified | Offset 3, 20433 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-file_ | 10 | ····<ocil:questionnaire·id="ocil:ssg-file_audit_tools_group_ownership_ocil:questionnaire:1"> |
11 | ······<ocil:title> | 11 | ······<ocil:title>Audit·Tools·Must·Be·Group-owned·by·Root</ocil:title> |
12 | ······<ocil:actions> | 12 | ······<ocil:actions> |
13 | ········<ocil:test_action_ref>ocil:ssg-file_ | 13 | ········<ocil:test_action_ref>ocil:ssg-file_audit_tools_group_ownership_action:testaction:1</ocil:test_action_ref> |
14 | ······</ocil:actions> | 14 | ······</ocil:actions> |
15 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
16 | ····<ocil:questionnaire·id="ocil:ssg-sebool_ | 16 | ····<ocil:questionnaire·id="ocil:ssg-sebool_httpd_ssi_exec_ocil:questionnaire:1"> |
17 | ······<ocil:title>Disable·the· | 17 | ······<ocil:title>Disable·the·httpd_ssi_exec·SELinux·Boolean</ocil:title> |
18 | ······<ocil:actions> | 18 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg-sebool_ | 19 | ········<ocil:test_action_ref>ocil:ssg-sebool_httpd_ssi_exec_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 20 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg-se | 22 | ····<ocil:questionnaire·id="ocil:ssg-sebool_exim_read_user_files_ocil:questionnaire:1"> |
23 | ······<ocil:title> | 23 | ······<ocil:title>Disable·the·exim_read_user_files·SELinux·Boolean</ocil:title> |
24 | ······<ocil:actions> | 24 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg-se | 25 | ········<ocil:test_action_ref>ocil:ssg-sebool_exim_read_user_files_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 26 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg- | 28 | ····<ocil:questionnaire·id="ocil:ssg-file_cron_allow_exists_ocil:questionnaire:1"> |
29 | ······<ocil:title> | 29 | ······<ocil:title>Ensure·that·/etc/cron.allow·exists</ocil:title> |
30 | ······<ocil:actions> | 30 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-file_cron_allow_exists_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 32 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1"> |
35 | ······<ocil:title>En | 35 | ······<ocil:title>Enable·cron·Service</ocil:title> |
36 | ······<ocil:actions> | 36 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 38 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 40 | ····<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1"> |
41 | ······<ocil:title>Disable· | 41 | ······<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title> |
42 | ······<ocil:actions> | 42 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 44 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_syn_cookies_ocil:questionnaire:1"> | ||
47 | ···· | 46 | ····<ocil:questionnaire·id="ocil:ssg-audit_modify_failed_ppc64le_ocil:questionnaire:1"> |
47 | ······<ocil:title>Configure·auditing·of·unsuccessful·file·modifications·(ppc64le)</ocil:title> | ||
48 | ······<ocil:actions> | 48 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-audit_modify_failed_ppc64le_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 50 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-sssd_certificate_verification_ocil:questionnaire:1"> | ||
53 | ···· | 52 | ····<ocil:questionnaire·id="ocil:ssg-sebool_httpd_can_network_relay_ocil:questionnaire:1"> |
53 | ······<ocil:title>Disable·the·httpd_can_network_relay·SELinux·Boolean</ocil:title> | ||
54 | ······<ocil:actions> | 54 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg-s | 55 | ········<ocil:test_action_ref>ocil:ssg-sebool_httpd_can_network_relay_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 56 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_issue_net_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 59 | ······<ocil:title>Verify·Group·Ownership·of·System·Login·Banner·for·Remote·Connections</ocil:title> |
60 | ······<ocil:actions> | 60 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_net_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 62 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_binaries_ocil:questionnaire:1"> |
65 | ······<ocil:title> | 65 | ······<ocil:title>Verify·that·audit·tools·are·owned·by·root</ocil:title> |
66 | ······<ocil:actions> | 66 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-file_ownership_audit_binaries_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 68 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-package_geolite2-city_removed_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 71 | ······<ocil:title>Uninstall·geolite2-city·Package</ocil:title> |
72 | ······<ocil:actions> | 72 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-package_geolite2-city_removed_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 74 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-sebool_cdrecord_read_content_ocil:questionnaire:1"> | ||
77 | ···· | 76 | ····<ocil:questionnaire·id="ocil:ssg-dnf-automatic_security_updates_only_ocil:questionnaire:1"> |
77 | ······<ocil:title>Configure·dnf-automatic·to·Install·Only·Security·Updates</ocil:title> | ||
78 | ······<ocil:actions> | 78 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-dnf-automatic_security_updates_only_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 80 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-s | 82 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 83 | ······<ocil:title>Disable·SSH·Support·for·.rhosts·Files</ocil:title> |
84 | ······<ocil:actions> | 84 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg-s | 85 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 86 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-bios_enable_execution_restrictions_ocil:questionnaire:1"> | ||
89 | ···· | 88 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1"> |
89 | ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title> | ||
90 | ······<ocil:actions> | 90 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 92 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_opasswd_ocil:questionnaire:1"> | ||
95 | ···· | 94 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_minlen_login_defs_ocil:questionnaire:1"> |
95 | ······<ocil:title>Set·Password·Minimum·Length·in·login.defs</ocil:title> | ||
96 | ······<ocil:actions> | 96 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg-a | 97 | ········<ocil:test_action_ref>ocil:ssg-accounts_password_minlen_login_defs_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 98 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-package_cryptsetup-luks_installed_ocil:questionnaire:1"> |
101 | ······<ocil:title> | 101 | ······<ocil:title>Install·cryptsetup·Package</ocil:title> |
102 | ······<ocil:actions> | 102 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-package_cryptsetup-luks_installed_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 104 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-sebool_zoneminder_anon_write_ocil:questionnaire:1"> | ||
107 | ···· | 106 | ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_interactive_users_ocil:questionnaire:1"> |
107 | ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·For·Interactive·Users</ocil:title> | ||
108 | ······<ocil:actions> | 108 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-accounts_umask_interactive_users_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 110 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg- | 112 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_chrony_keys_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 113 | ······<ocil:title>Verify·User·Who·Owns·/etc/chrony.keys·File</ocil:title> |
114 | ······<ocil:actions> | 114 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 115 | ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_chrony_keys_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 116 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 117 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg- | 118 | ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_cis_ocil:questionnaire:1"> |
119 | ······<ocil:title> | 119 | ······<ocil:title>Ensure·Local·Login·Warning·Banner·Is·Configured·Properly</ocil:title> |
120 | ······<ocil:actions> | 120 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg- | 121 | ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_cis_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 122 | ······</ocil:actions> |
123 | ····</ocil:questionnaire> | 123 | ····</ocil:questionnaire> |
Max diff block lines reached; 3297984/3310654 bytes (99.62%) of diff not shown. |
Offset 19, 27 lines modified | Offset 19, 27 lines modified | ||
19 | ····</ds:checklists> | 19 | ····</ds:checklists> |
20 | ····<ds:checks> | 20 | ····<ds:checks> |
21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-oval.xml"/> | 21 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-oval.xml"/> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-ocil.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-ocil.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-cpe-oval.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-cpe-oval.xml"/> |
24 | ····</ds:checks> | 24 | ····</ds:checks> |
25 | ··</ds:data-stream> | 25 | ··</ds:data-stream> |
26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-cpe-dictionary.xml"·timestamp="2025-0 | 26 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 27 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
28 | ······<cpe-dict:cpe-item·name="cpe:/a:redhat:enterprise_virtualization_manager:4"> | 28 | ······<cpe-dict:cpe-item·name="cpe:/a:redhat:enterprise_virtualization_manager:4"> |
29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Manager</cpe-dict:title> | 29 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Manager</cpe-dict:title> |
30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_app_is_rhv4:def:1</cpe-dict:check> | 30 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_app_is_rhv4:def:1</cpe-dict:check> |
31 | ······</cpe-dict:cpe-item> | 31 | ······</cpe-dict:cpe-item> |
32 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8::hypervisor"> | 32 | ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8::hypervisor"> |
33 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Host</cpe-dict:title> | 33 | ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Host</cpe-dict:title> |
34 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_OS_is_rhv4:def:1</cpe-dict:check> | 34 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_OS_is_rhv4:def:1</cpe-dict:check> |
35 | ······</cpe-dict:cpe-item> | 35 | ······</cpe-dict:cpe-item> |
36 | ····</cpe-dict:cpe-list> | 36 | ····</cpe-dict:cpe-list> |
37 | ··</ds:component> | 37 | ··</ds:component> |
38 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-xccdf.xml"·timestamp="2025-0 | 38 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
39 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHV-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 39 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHV-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
40 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 40 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
41 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Virtualization·4</xccdf-1.2:title> | 41 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Virtualization·4</xccdf-1.2:title> |
42 | ······<xccdf-1.2:description> | 42 | ······<xccdf-1.2:description> |
43 | ········This·guide·presents·a·catalog·of·security-relevant | 43 | ········This·guide·presents·a·catalog·of·security-relevant |
44 | configuration·settings·for·Red·Hat·Virtualization·4.·It·is·a·rendering·of | 44 | configuration·settings·for·Red·Hat·Virtualization·4.·It·is·a·rendering·of |
45 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 45 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 162832, 15 lines modified | Offset 162832, 15 lines modified | ||
162832 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhv4-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> | 162832 | ··············<xccdf-1.2:check-content-ref·href="ssg-rhv4-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> |
162833 | ············</xccdf-1.2:check> | 162833 | ············</xccdf-1.2:check> |
162834 | ··········</xccdf-1.2:Rule> | 162834 | ··········</xccdf-1.2:Rule> |
162835 | ········</xccdf-1.2:Group> | 162835 | ········</xccdf-1.2:Group> |
162836 | ······</xccdf-1.2:Group> | 162836 | ······</xccdf-1.2:Group> |
162837 | ····</xccdf-1.2:Benchmark> | 162837 | ····</xccdf-1.2:Benchmark> |
162838 | ··</ds:component> | 162838 | ··</ds:component> |
162839 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-oval.xml"·timestamp="2025-0 | 162839 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-oval.xml"·timestamp="2025-03-01T22:08:00"> |
162840 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 162840 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
162841 | ······<oval-def:generator> | 162841 | ······<oval-def:generator> |
162842 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 162842 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
162843 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 162843 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
162844 | ········<oval:schema_version>5.11</oval:schema_version> | 162844 | ········<oval:schema_version>5.11</oval:schema_version> |
162845 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 162845 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
162846 | ······</oval-def:generator> | 162846 | ······</oval-def:generator> |
Offset 195359, 6372 lines modified | Offset 195359, 6372 lines modified | ||
195359 | ············</oval-def:arithmetic> | 195359 | ············</oval-def:arithmetic> |
195360 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 195360 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
195361 | ··········</oval-def:arithmetic> | 195361 | ··········</oval-def:arithmetic> |
195362 | ········</oval-def:local_variable> | 195362 | ········</oval-def:local_variable> |
195363 | ······</oval-def:variables> | 195363 | ······</oval-def:variables> |
195364 | ····</oval-def:oval_definitions> | 195364 | ····</oval-def:oval_definitions> |
195365 | ··</ds:component> | 195365 | ··</ds:component> |
195366 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-ocil.xml"·timestamp="2025-0 | 195366 | ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
195367 | ····<ocil:ocil> | 195367 | ····<ocil:ocil> |
195368 | ······<ocil:generator> | 195368 | ······<ocil:generator> |
195369 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 195369 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
195370 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 195370 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
195371 | ········<ocil:schema_version>2.0</ocil:schema_version> | 195371 | ········<ocil:schema_version>2.0</ocil:schema_version> |
195372 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 195372 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
195373 | ······</ocil:generator> | 195373 | ······</ocil:generator> |
195374 | ······<ocil:questionnaires> | 195374 | ······<ocil:questionnaires> |
195375 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 195375 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1"> |
195376 | ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title> | ||
195376 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount2</ocil:title> | ||
195377 | ··········<ocil:actions> | ||
195378 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount2_action:testaction:1</ocil:test_action_ref> | ||
195379 | ··········</ocil:actions> | ||
195380 | ········</ocil:questionnaire> | ||
195381 | ········<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1"> | ||
195382 | ··········<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title> | ||
195383 | ··········<ocil:actions> | ||
195384 | ············<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref> | ||
195385 | ··········</ocil:actions> | ||
195386 | ········</ocil:questionnaire> | ||
195387 | ········<ocil:questionnaire·id="ocil:ssg-directory_access_var_log_audit_ocil:questionnaire:1"> | ||
195388 | ··········<ocil:title>Record·Access·Events·to·Audit·Log·Directory</ocil:title> | ||
195389 | ··········<ocil:actions> | 195377 | ··········<ocil:actions> |
195390 | ············<ocil:test_action_ref>ocil:ssg-di | 195378 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref> |
195391 | ··········</ocil:actions> | 195379 | ··········</ocil:actions> |
195392 | ········</ocil:questionnaire> | 195380 | ········</ocil:questionnaire> |
195393 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 195381 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1"> |
195394 | ··········<ocil:title>Record· | 195382 | ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title> |
195395 | ··········<ocil:actions> | 195383 | ··········<ocil:actions> |
195396 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_ | 195384 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref> |
195397 | ··········</ocil:actions> | 195385 | ··········</ocil:actions> |
195398 | ········</ocil:questionnaire> | 195386 | ········</ocil:questionnaire> |
195399 | ········<ocil:questionnaire·id="ocil:ssg-mount_option_home_usrquota_ocil:questionnaire:1"> | ||
195400 | ········ | 195387 | ········<ocil:questionnaire·id="ocil:ssg-auditd_audispd_encrypt_sent_records_ocil:questionnaire:1"> |
195388 | ··········<ocil:title>Encrypt·Audit·Records·Sent·With·audispd·Plugin</ocil:title> | ||
195401 | ··········<ocil:actions> | 195389 | ··········<ocil:actions> |
195402 | ············<ocil:test_action_ref>ocil:ssg- | 195390 | ············<ocil:test_action_ref>ocil:ssg-auditd_audispd_encrypt_sent_records_action:testaction:1</ocil:test_action_ref> |
195403 | ··········</ocil:actions> | 195391 | ··········</ocil:actions> |
195404 | ········</ocil:questionnaire> | 195392 | ········</ocil:questionnaire> |
195405 | ········<ocil:questionnaire·id="ocil:ssg- | 195393 | ········<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1"> |
195406 | ··········<ocil:title> | 195394 | ··········<ocil:title>Disable·the·Automounter</ocil:title> |
195407 | ··········<ocil:actions> | 195395 | ··········<ocil:actions> |
195408 | ············<ocil:test_action_ref>ocil:ssg- | 195396 | ············<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref> |
195409 | ··········</ocil:actions> | 195397 | ··········</ocil:actions> |
195410 | ········</ocil:questionnaire> | 195398 | ········</ocil:questionnaire> |
195411 | ········<ocil:questionnaire·id="ocil:ssg- | 195399 | ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1"> |
195412 | ··········<ocil:title> | 195400 | ··········<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title> |
195413 | ··········<ocil:actions> | 195401 | ··········<ocil:actions> |
195414 | ············<ocil:test_action_ref>ocil:ssg- | 195402 | ············<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref> |
195415 | ··········</ocil:actions> | 195403 | ··········</ocil:actions> |
195416 | ········</ocil:questionnaire> | 195404 | ········</ocil:questionnaire> |
195417 | ········<ocil:questionnaire·id="ocil:ssg- | 195405 | ········<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1"> |
195418 | ··········<ocil:title> | 195406 | ··········<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title> |
195419 | ··········<ocil:actions> | 195407 | ··········<ocil:actions> |
195420 | ············<ocil:test_action_ref>ocil:ssg- | 195408 | ············<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref> |
195421 | ··········</ocil:actions> | 195409 | ··········</ocil:actions> |
195422 | ········</ocil:questionnaire> | 195410 | ········</ocil:questionnaire> |
195423 | ········<ocil:questionnaire·id="ocil:ssg- | 195411 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_sshd_config_ocil:questionnaire:1"> |
195424 | ··········<ocil:title> | 195412 | ··········<ocil:title>Verify·Owner·on·SSH·Server·config·file</ocil:title> |
195425 | ··········<ocil:actions> | 195413 | ··········<ocil:actions> |
195426 | ············<ocil:test_action_ref>ocil:ssg- | 195414 | ············<ocil:test_action_ref>ocil:ssg-file_owner_sshd_config_action:testaction:1</ocil:test_action_ref> |
195427 | ··········</ocil:actions> | 195415 | ··········</ocil:actions> |
195428 | ········</ocil:questionnaire> | 195416 | ········</ocil:questionnaire> |
195429 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_removexattr_ocil:questionnaire:1"> | ||
195430 | ········ | 195417 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_ocil:questionnaire:1"> |
195418 | ··········<ocil:title>Enable·Kernel·Parameter·to·Log·Martian·Packets·on·all·IPv4·Interfaces</ocil:title> | ||
195431 | ··········<ocil:actions> | 195419 | ··········<ocil:actions> |
195432 | ············<ocil:test_action_ref>ocil:ssg- | 195420 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_action:testaction:1</ocil:test_action_ref> |
195433 | ··········</ocil:actions> | 195421 | ··········</ocil:actions> |
195434 | ········</ocil:questionnaire> | 195422 | ········</ocil:questionnaire> |
195435 | ········<ocil:questionnaire·id="ocil:ssg- | 195423 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1"> |
195436 | ··········<ocil:title> | 195424 | ··········<ocil:title>Verify·Group·Who·Owns·/var/log/messages·File</ocil:title> |
195437 | ··········<ocil:actions> | 195425 | ··········<ocil:actions> |
195438 | ············<ocil:test_action_ref>ocil:ssg- | 195426 | ············<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_messages_action:testaction:1</ocil:test_action_ref> |
Max diff block lines reached; 1631274/1642888 bytes (99.29%) of diff not shown. |
Offset 3, 6363 lines modified | Offset 3, 6363 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 10 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1"> |
11 | ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title> | ||
11 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount2</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount2_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1"> | ||
17 | ······<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title> | ||
18 | ······<ocil:actions> | ||
19 | ········<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref> | ||
20 | ······</ocil:actions> | ||
21 | ····</ocil:questionnaire> | ||
22 | ····<ocil:questionnaire·id="ocil:ssg-directory_access_var_log_audit_ocil:questionnaire:1"> | ||
23 | ······<ocil:title>Record·Access·Events·to·Audit·Log·Directory</ocil:title> | ||
24 | ······<ocil:actions> | 12 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg-di | 13 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 14 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 16 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1"> |
29 | ······<ocil:title>Record· | 17 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title> |
30 | ······<ocil:actions> | 18 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_ | 19 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 20 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_usrquota_ocil:questionnaire:1"> | ||
35 | ···· | 22 | ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_encrypt_sent_records_ocil:questionnaire:1"> |
23 | ······<ocil:title>Encrypt·Audit·Records·Sent·With·audispd·Plugin</ocil:title> | ||
36 | ······<ocil:actions> | 24 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_encrypt_sent_records_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 26 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 28 | ····<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1"> |
41 | ······<ocil:title> | 29 | ······<ocil:title>Disable·the·Automounter</ocil:title> |
42 | ······<ocil:actions> | 30 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 32 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1"> |
47 | ······<ocil:title> | 35 | ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title> |
48 | ······<ocil:actions> | 36 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 38 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg- | 40 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1"> |
53 | ······<ocil:title> | 41 | ······<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title> |
54 | ······<ocil:actions> | 42 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 44 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg- | 46 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_sshd_config_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 47 | ······<ocil:title>Verify·Owner·on·SSH·Server·config·file</ocil:title> |
60 | ······<ocil:actions> | 48 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-file_owner_sshd_config_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 50 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_removexattr_ocil:questionnaire:1"> | ||
65 | ···· | 52 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_ocil:questionnaire:1"> |
53 | ······<ocil:title>Enable·Kernel·Parameter·to·Log·Martian·Packets·on·all·IPv4·Interfaces</ocil:title> | ||
66 | ······<ocil:actions> | 54 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 56 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 58 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 59 | ······<ocil:title>Verify·Group·Who·Owns·/var/log/messages·File</ocil:title> |
72 | ······<ocil:actions> | 60 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_messages_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 62 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"> | ||
77 | ···· | 64 | ····<ocil:questionnaire·id="ocil:ssg-grub2_mce_argument_ocil:questionnaire:1"> |
65 | ······<ocil:title>Force·kernel·panic·on·uncorrected·MCEs</ocil:title> | ||
78 | ······<ocil:actions> | 66 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-grub2_mce_argument_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 68 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-s | 70 | ····<ocil:questionnaire·id="ocil:ssg-service_zebra_disabled_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 71 | ······<ocil:title>Disable·Quagga·Service</ocil:title> |
84 | ······<ocil:actions> | 72 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg-s | 73 | ········<ocil:test_action_ref>ocil:ssg-service_zebra_disabled_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 74 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-a | 76 | ····<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 77 | ······<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title> |
90 | ······<ocil:actions> | 78 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg-a | 79 | ········<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 80 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1"> | ||
95 | ···· | 82 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1"> |
83 | ······<ocil:title>Kernel·panic·oops</ocil:title> | ||
96 | ······<ocil:actions> | 84 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_on_oops_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 86 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1"> | ||
101 | ···· | 88 | ····<ocil:questionnaire·id="ocil:ssg-sebool_xdm_exec_bootloader_ocil:questionnaire:1"> |
89 | ······<ocil:title>Disable·the·xdm_exec_bootloader·SELinux·Boolean</ocil:title> | ||
102 | ······<ocil:actions> | 90 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-sebool_xdm_exec_bootloader_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 92 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-audit_ | 94 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 95 | ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title> |
108 | ······<ocil:actions> | 96 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg-audit_ | 97 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 98 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-service_ | 100 | ····<ocil:questionnaire·id="ocil:ssg-service_sshd_enabled_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 101 | ······<ocil:title>Enable·the·OpenSSH·Service</ocil:title> |
114 | ······<ocil:actions> | 102 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg-service_ | 103 | ········<ocil:test_action_ref>ocil:ssg-service_sshd_enabled_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 104 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-set_firewalld_default_zone_ocil:questionnaire:1"> | ||
119 | ···· | 106 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1"> |
107 | ······<ocil:title>Verify·Permissions·on·gshadow·File</ocil:title> | ||
120 | ······<ocil:actions> | 108 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_gshadow_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 110 | ······</ocil:actions> |
Max diff block lines reached; 1558457/1570499 bytes (99.23%) of diff not shown. |
Offset 21, 27 lines modified | Offset 21, 27 lines modified | ||
21 | ····<ds:checks> | 21 | ····<ds:checks> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-oval.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-oval.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-ocil.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-ocil.xml"/> |
24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-cpe-oval.xml"/> | 24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-cpe-oval.xml"/> |
25 | ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.12-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.12-patch.xml.bz2"/> | 25 | ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.12-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.12-patch.xml.bz2"/> |
26 | ····</ds:checks> | 26 | ····</ds:checks> |
27 | ··</ds:data-stream> | 27 | ··</ds:data-stream> |
28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-cpe-dictionary.xml"·timestamp="2025-0 | 28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
30 | ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:12"> | 30 | ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:12"> |
31 | ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·12</cpe-dict:title> | 31 | ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·12</cpe-dict:title> |
32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check> | 32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check> |
33 | ······</cpe-dict:cpe-item> | 33 | ······</cpe-dict:cpe-item> |
34 | ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:12"> | 34 | ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:12"> |
35 | ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·12</cpe-dict:title> | 35 | ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·12</cpe-dict:title> |
36 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check> | 36 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check> |
37 | ······</cpe-dict:cpe-item> | 37 | ······</cpe-dict:cpe-item> |
38 | ····</cpe-dict:cpe-list> | 38 | ····</cpe-dict:cpe-list> |
39 | ··</ds:component> | 39 | ··</ds:component> |
40 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-xccdf.xml"·timestamp="2025-0 | 40 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
41 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 41 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
42 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 42 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
43 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·12</xccdf-1.2:title> | 43 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·12</xccdf-1.2:title> |
44 | ······<xccdf-1.2:description> | 44 | ······<xccdf-1.2:description> |
45 | ········This·guide·presents·a·catalog·of·security-relevant | 45 | ········This·guide·presents·a·catalog·of·security-relevant |
46 | configuration·settings·for·SUSE·Linux·Enterprise·12.·It·is·a·rendering·of | 46 | configuration·settings·for·SUSE·Linux·Enterprise·12.·It·is·a·rendering·of |
47 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 47 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 186684, 15 lines modified | Offset 186684, 15 lines modified | ||
186684 | ··············<xccdf-1.2:check-content-ref·href="ssg-sle12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> | 186684 | ··············<xccdf-1.2:check-content-ref·href="ssg-sle12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> |
186685 | ············</xccdf-1.2:check> | 186685 | ············</xccdf-1.2:check> |
186686 | ··········</xccdf-1.2:Rule> | 186686 | ··········</xccdf-1.2:Rule> |
186687 | ········</xccdf-1.2:Group> | 186687 | ········</xccdf-1.2:Group> |
186688 | ······</xccdf-1.2:Group> | 186688 | ······</xccdf-1.2:Group> |
186689 | ····</xccdf-1.2:Benchmark> | 186689 | ····</xccdf-1.2:Benchmark> |
186690 | ··</ds:component> | 186690 | ··</ds:component> |
186691 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-oval.xml"·timestamp="2025-0 | 186691 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-oval.xml"·timestamp="2025-03-01T22:08:00"> |
186692 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 186692 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
186693 | ······<oval-def:generator> | 186693 | ······<oval-def:generator> |
186694 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 186694 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
186695 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 186695 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
186696 | ········<oval:schema_version>5.11</oval:schema_version> | 186696 | ········<oval:schema_version>5.11</oval:schema_version> |
186697 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 186697 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
186698 | ······</oval-def:generator> | 186698 | ······</oval-def:generator> |
Offset 227001, 12188 lines modified | Offset 227001, 12270 lines modified | ||
227001 | ············</oval-def:arithmetic> | 227001 | ············</oval-def:arithmetic> |
227002 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 227002 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
227003 | ··········</oval-def:arithmetic> | 227003 | ··········</oval-def:arithmetic> |
227004 | ········</oval-def:local_variable> | 227004 | ········</oval-def:local_variable> |
227005 | ······</oval-def:variables> | 227005 | ······</oval-def:variables> |
227006 | ····</oval-def:oval_definitions> | 227006 | ····</oval-def:oval_definitions> |
227007 | ··</ds:component> | 227007 | ··</ds:component> |
227008 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-ocil.xml"·timestamp="2025-0 | 227008 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
227009 | ····<ocil:ocil> | 227009 | ····<ocil:ocil> |
227010 | ······<ocil:generator> | 227010 | ······<ocil:generator> |
227011 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 227011 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
227012 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 227012 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
227013 | ········<ocil:schema_version>2.0</ocil:schema_version> | 227013 | ········<ocil:schema_version>2.0</ocil:schema_version> |
227014 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 227014 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
227015 | ······</ocil:generator> | 227015 | ······</ocil:generator> |
227016 | ······<ocil:questionnaires> | 227016 | ······<ocil:questionnaires> |
227017 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_rmmod_ocil:questionnaire:1"> | ||
227018 | ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·rmmod</ocil:title> | ||
227019 | ··········<ocil:actions> | ||
227020 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_rmmod_action:testaction:1</ocil:test_action_ref> | ||
227021 | ··········</ocil:actions> | ||
227022 | ········</ocil:questionnaire> | ||
227023 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 227017 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1"> |
227024 | ··········<ocil:title>Ensure·auditd·Collects·Information·on· | 227018 | ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title> |
227025 | ··········<ocil:actions> | ||
227026 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_umount_action:testaction:1</ocil:test_action_ref> | ||
227027 | ··········</ocil:actions> | ||
227028 | ········</ocil:questionnaire> | ||
227029 | ········<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1"> | ||
227030 | ··········<ocil:title>Disable·the·Automounter</ocil:title> | ||
227031 | ··········<ocil:actions> | ||
227032 | ············<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref> | ||
227033 | ··········</ocil:actions> | ||
227034 | ········</ocil:questionnaire> | ||
227035 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_ocil:questionnaire:1"> | ||
227036 | ··········<ocil:title>Configure·Accepting·Default·Router·in·Router·Advertisements·on·All·IPv6·Interfaces·By·Default</ocil:title> | ||
227037 | ··········<ocil:actions> | ||
227038 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_action:testaction:1</ocil:test_action_ref> | ||
227039 | ··········</ocil:actions> | ||
227040 | ········</ocil:questionnaire> | ||
227041 | ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1"> | ||
227042 | ··········<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title> | ||
227043 | ··········<ocil:actions> | ||
227044 | ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref> | ||
227045 | ··········</ocil:actions> | ||
227046 | ········</ocil:questionnaire> | ||
227047 | ········<ocil:questionnaire·id="ocil:ssg-auditd_audispd_network_failure_action_ocil:questionnaire:1"> | ||
227048 | ··········<ocil:title>Configure·audispd's·Plugin·network_failure_action·On·Network·Failure</ocil:title> | ||
227049 | ··········<ocil:actions> | 227019 | ··········<ocil:actions> |
227050 | ············<ocil:test_action_ref>ocil:ssg-audit | 227020 | ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref> |
227051 | ··········</ocil:actions> | 227021 | ··········</ocil:actions> |
227052 | ········</ocil:questionnaire> | 227022 | ········</ocil:questionnaire> |
227053 | ········<ocil:questionnaire·id="ocil:ssg-ss | 227023 | ········<ocil:questionnaire·id="ocil:ssg-susefirewall2_only_required_services_ocil:questionnaire:1"> |
227054 | ··········<ocil:title> | 227024 | ··········<ocil:title>Only·Allow·Authorized·Network·Services·in·SuSEfirewall2</ocil:title> |
227055 | ··········<ocil:actions> | 227025 | ··········<ocil:actions> |
227056 | ············<ocil:test_action_ref>ocil:ssg-ss | 227026 | ············<ocil:test_action_ref>ocil:ssg-susefirewall2_only_required_services_action:testaction:1</ocil:test_action_ref> |
227057 | ··········</ocil:actions> | 227027 | ··········</ocil:actions> |
227058 | ········</ocil:questionnaire> | 227028 | ········</ocil:questionnaire> |
227059 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1"> | ||
227060 | ········ | 227029 | ········<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1"> |
227030 | ··········<ocil:title>Do·Not·Allow·SSH·Environment·Options</ocil:title> | ||
227061 | ··········<ocil:actions> | 227031 | ··········<ocil:actions> |
227062 | ············<ocil:test_action_ref>ocil:ssg- | 227032 | ············<ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref> |
227063 | ··········</ocil:actions> | 227033 | ··········</ocil:actions> |
227064 | ········</ocil:questionnaire> | 227034 | ········</ocil:questionnaire> |
227065 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_newgrp_ocil:questionnaire:1"> | ||
227066 | ········ | 227035 | ········<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1"> |
227036 | ··········<ocil:title>Set·PAM''s·Password·Hashing·Algorithm</ocil:title> | ||
227067 | ··········<ocil:actions> | 227037 | ··········<ocil:actions> |
227068 | ············<ocil:test_action_ref>ocil:ssg- | 227038 | ············<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref> |
227069 | ··········</ocil:actions> | 227039 | ··········</ocil:actions> |
227070 | ········</ocil:questionnaire> | 227040 | ········</ocil:questionnaire> |
227071 | ········<ocil:questionnaire·id="ocil:ssg- | 227041 | ········<ocil:questionnaire·id="ocil:ssg-no_forward_files_ocil:questionnaire:1"> |
227072 | ··········<ocil:title>Verify· | 227042 | ··········<ocil:title>Verify·No·.forward·Files·Exist</ocil:title> |
227073 | ··········<ocil:actions> | 227043 | ··········<ocil:actions> |
227074 | ············<ocil:test_action_ref>ocil:ssg- | 227044 | ············<ocil:test_action_ref>ocil:ssg-no_forward_files_action:testaction:1</ocil:test_action_ref> |
227075 | ··········</ocil:actions> | 227045 | ··········</ocil:actions> |
227076 | ········</ocil:questionnaire> | 227046 | ········</ocil:questionnaire> |
227077 | ········<ocil:questionnaire·id="ocil:ssg- | 227047 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_chrony_keys_ocil:questionnaire:1"> |
227078 | ··········<ocil:title> | 227048 | ··········<ocil:title>Verify·User·Who·Owns·/etc/chrony.keys·File</ocil:title> |
227079 | ··········<ocil:actions> | 227049 | ··········<ocil:actions> |
227080 | ············<ocil:test_action_ref>ocil:ssg- | 227050 | ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_chrony_keys_action:testaction:1</ocil:test_action_ref> |
227081 | ··········</ocil:actions> | 227051 | ··········</ocil:actions> |
Max diff block lines reached; 1859197/1870340 bytes (99.40%) of diff not shown. |
Offset 3, 12179 lines modified | Offset 3, 12261 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_rmmod_ocil:questionnaire:1"> | ||
11 | ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·rmmod</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_rmmod_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 10 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1"> |
17 | ······<ocil:title>Ensure·auditd·Collects·Information·on· | 11 | ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title> |
18 | ······<ocil:actions> | ||
19 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_umount_action:testaction:1</ocil:test_action_ref> | ||
20 | ······</ocil:actions> | ||
21 | ····</ocil:questionnaire> | ||
22 | ····<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1"> | ||
23 | ······<ocil:title>Disable·the·Automounter</ocil:title> | ||
24 | ······<ocil:actions> | ||
25 | ········<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref> | ||
26 | ······</ocil:actions> | ||
27 | ····</ocil:questionnaire> | ||
28 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_ocil:questionnaire:1"> | ||
29 | ······<ocil:title>Configure·Accepting·Default·Router·in·Router·Advertisements·on·All·IPv6·Interfaces·By·Default</ocil:title> | ||
30 | ······<ocil:actions> | ||
31 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_action:testaction:1</ocil:test_action_ref> | ||
32 | ······</ocil:actions> | ||
33 | ····</ocil:questionnaire> | ||
34 | ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1"> | ||
35 | ······<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title> | ||
36 | ······<ocil:actions> | ||
37 | ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref> | ||
38 | ······</ocil:actions> | ||
39 | ····</ocil:questionnaire> | ||
40 | ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_network_failure_action_ocil:questionnaire:1"> | ||
41 | ······<ocil:title>Configure·audispd's·Plugin·network_failure_action·On·Network·Failure</ocil:title> | ||
42 | ······<ocil:actions> | 12 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg-audit | 13 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 14 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg-ss | 16 | ····<ocil:questionnaire·id="ocil:ssg-susefirewall2_only_required_services_ocil:questionnaire:1"> |
47 | ······<ocil:title> | 17 | ······<ocil:title>Only·Allow·Authorized·Network·Services·in·SuSEfirewall2</ocil:title> |
48 | ······<ocil:actions> | 18 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg-ss | 19 | ········<ocil:test_action_ref>ocil:ssg-susefirewall2_only_required_services_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 20 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1"> | ||
53 | ···· | 22 | ····<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1"> |
23 | ······<ocil:title>Do·Not·Allow·SSH·Environment·Options</ocil:title> | ||
54 | ······<ocil:actions> | 24 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 26 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_newgrp_ocil:questionnaire:1"> | ||
59 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1"> |
29 | ······<ocil:title>Set·PAM''s·Password·Hashing·Algorithm</ocil:title> | ||
60 | ······<ocil:actions> | 30 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 32 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-no_forward_files_ocil:questionnaire:1"> |
65 | ······<ocil:title>Verify· | 35 | ······<ocil:title>Verify·No·.forward·Files·Exist</ocil:title> |
66 | ······<ocil:actions> | 36 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-no_forward_files_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 38 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 40 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_chrony_keys_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 41 | ······<ocil:title>Verify·User·Who·Owns·/etc/chrony.keys·File</ocil:title> |
72 | ······<ocil:actions> | 42 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_chrony_keys_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 44 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1"> | ||
77 | ···· | 46 | ····<ocil:questionnaire·id="ocil:ssg-journald_compress_ocil:questionnaire:1"> |
47 | ······<ocil:title>Ensure·journald·is·configured·to·compress·large·log·files</ocil:title> | ||
78 | ······<ocil:actions> | 48 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-journald_compress_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 50 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg- | 52 | ····<ocil:questionnaire·id="ocil:ssg-accounts_user_interactive_home_directory_exists_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 53 | ······<ocil:title>All·Interactive·Users·Home·Directories·Must·Exist</ocil:title> |
84 | ······<ocil:actions> | 54 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-accounts_user_interactive_home_directory_exists_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 56 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1"> | ||
89 | ···· | 58 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_sshd_config_ocil:questionnaire:1"> |
59 | ······<ocil:title>Verify·Group·Who·Owns·SSH·Server·config·file</ocil:title> | ||
90 | ······<ocil:actions> | 60 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_sshd_config_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 62 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 65 | ······<ocil:title>Install·the·cron·service</ocil:title> |
96 | ······<ocil:actions> | 66 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 68 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-s | 70 | ····<ocil:questionnaire·id="ocil:ssg-service_kdump_disabled_ocil:questionnaire:1"> |
101 | ······<ocil:title>Disable· | 71 | ······<ocil:title>Disable·KDump·Kernel·Crash·Analyzer·(kdump)</ocil:title> |
102 | ······<ocil:actions> | 72 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg-s | 73 | ········<ocil:test_action_ref>ocil:ssg-service_kdump_disabled_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 74 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-file_ | 76 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 77 | ······<ocil:title>System·Audit·Logs·Must·Be·Owned·By·Root</ocil:title> |
108 | ······<ocil:actions> | 78 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg-file_ | 79 | ········<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 80 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg- | 82 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 83 | ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title> |
114 | ······<ocil:actions> | 84 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 86 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_ | 88 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1"> |
119 | ······<ocil:title>Ensure·auditd·Collects· | 89 | ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title> |
120 | ······<ocil:actions> | 90 | ······<ocil:actions> |
121 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_ | 91 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref> |
122 | ······</ocil:actions> | 92 | ······</ocil:actions> |
123 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
124 | ····<ocil:questionnaire·id="ocil:ssg- | 94 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_weekly_ocil:questionnaire:1"> |
125 | ······<ocil:title> | 95 | ······<ocil:title>Verify·Group·Who·Owns·cron.weekly</ocil:title> |
Max diff block lines reached; 1776660/1788472 bytes (99.34%) of diff not shown. |
Offset 21, 27 lines modified | Offset 21, 27 lines modified | ||
21 | ····<ds:checks> | 21 | ····<ds:checks> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-oval.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-oval.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-ocil.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-ocil.xml"/> |
24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-cpe-oval.xml"/> | 24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-cpe-oval.xml"/> |
25 | ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.15-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.15-patch.xml.bz2"/> | 25 | ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.15-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.15-patch.xml.bz2"/> |
26 | ····</ds:checks> | 26 | ····</ds:checks> |
27 | ··</ds:data-stream> | 27 | ··</ds:data-stream> |
28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-cpe-dictionary.xml"·timestamp="2025-0 | 28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
30 | ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:15"> | 30 | ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:15"> |
31 | ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·15</cpe-dict:title> | 31 | ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·15</cpe-dict:title> |
32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check> | 32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check> |
33 | ······</cpe-dict:cpe-item> | 33 | ······</cpe-dict:cpe-item> |
34 | ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:15"> | 34 | ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:15"> |
35 | ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·15</cpe-dict:title> | 35 | ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·15</cpe-dict:title> |
36 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check> | 36 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check> |
37 | ······</cpe-dict:cpe-item> | 37 | ······</cpe-dict:cpe-item> |
38 | ····</cpe-dict:cpe-list> | 38 | ····</cpe-dict:cpe-list> |
39 | ··</ds:component> | 39 | ··</ds:component> |
40 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-xccdf.xml"·timestamp="2025-0 | 40 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
41 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-15"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 41 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-15"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
42 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 42 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
43 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·15</xccdf-1.2:title> | 43 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·15</xccdf-1.2:title> |
44 | ······<xccdf-1.2:description> | 44 | ······<xccdf-1.2:description> |
45 | ········This·guide·presents·a·catalog·of·security-relevant | 45 | ········This·guide·presents·a·catalog·of·security-relevant |
46 | configuration·settings·for·SUSE·Linux·Enterprise·15.·It·is·a·rendering·of | 46 | configuration·settings·for·SUSE·Linux·Enterprise·15.·It·is·a·rendering·of |
47 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 47 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 200277, 15 lines modified | Offset 200277, 15 lines modified | ||
200277 | ··············<xccdf-1.2:check-content-ref·href="ssg-sle15-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> | 200277 | ··············<xccdf-1.2:check-content-ref·href="ssg-sle15-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/> |
200278 | ············</xccdf-1.2:check> | 200278 | ············</xccdf-1.2:check> |
200279 | ··········</xccdf-1.2:Rule> | 200279 | ··········</xccdf-1.2:Rule> |
200280 | ········</xccdf-1.2:Group> | 200280 | ········</xccdf-1.2:Group> |
200281 | ······</xccdf-1.2:Group> | 200281 | ······</xccdf-1.2:Group> |
200282 | ····</xccdf-1.2:Benchmark> | 200282 | ····</xccdf-1.2:Benchmark> |
200283 | ··</ds:component> | 200283 | ··</ds:component> |
200284 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-oval.xml"·timestamp="2025-0 | 200284 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-oval.xml"·timestamp="2025-03-01T22:08:00"> |
200285 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 200285 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
200286 | ······<oval-def:generator> | 200286 | ······<oval-def:generator> |
200287 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 200287 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
200288 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 200288 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
200289 | ········<oval:schema_version>5.11</oval:schema_version> | 200289 | ········<oval:schema_version>5.11</oval:schema_version> |
200290 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 200290 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
200291 | ······</oval-def:generator> | 200291 | ······</oval-def:generator> |
Offset 242596, 9925 lines modified | Offset 242596, 9925 lines modified | ||
242596 | ············</oval-def:arithmetic> | 242596 | ············</oval-def:arithmetic> |
242597 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 242597 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
242598 | ··········</oval-def:arithmetic> | 242598 | ··········</oval-def:arithmetic> |
242599 | ········</oval-def:local_variable> | 242599 | ········</oval-def:local_variable> |
242600 | ······</oval-def:variables> | 242600 | ······</oval-def:variables> |
242601 | ····</oval-def:oval_definitions> | 242601 | ····</oval-def:oval_definitions> |
242602 | ··</ds:component> | 242602 | ··</ds:component> |
242603 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-ocil.xml"·timestamp="2025-0 | 242603 | ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
242604 | ····<ocil:ocil> | 242604 | ····<ocil:ocil> |
242605 | ······<ocil:generator> | 242605 | ······<ocil:generator> |
242606 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 242606 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
242607 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 242607 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
242608 | ········<ocil:schema_version>2.0</ocil:schema_version> | 242608 | ········<ocil:schema_version>2.0</ocil:schema_version> |
242609 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 242609 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
242610 | ······</ocil:generator> | 242610 | ······</ocil:generator> |
242611 | ······<ocil:questionnaires> | 242611 | ······<ocil:questionnaires> |
242612 | ········<ocil:questionnaire·id="ocil:ssg-service_debug-shell_disabled_ocil:questionnaire:1"> | ||
242613 | ··········<ocil:title>Disable·debug-shell·SystemD·Service</ocil:title> | ||
242614 | ··········<ocil:actions> | ||
242615 | ············<ocil:test_action_ref>ocil:ssg-service_debug-shell_disabled_action:testaction:1</ocil:test_action_ref> | ||
242616 | ··········</ocil:actions> | ||
242617 | ········</ocil:questionnaire> | ||
242618 | ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_nodev_ocil:questionnaire:1"> | 242612 | ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_nodev_ocil:questionnaire:1"> |
242619 | ··········<ocil:title>Add·nodev·Option·to·/var/tmp</ocil:title> | 242613 | ··········<ocil:title>Add·nodev·Option·to·/var/tmp</ocil:title> |
242620 | ··········<ocil:actions> | 242614 | ··········<ocil:actions> |
242621 | ············<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_nodev_action:testaction:1</ocil:test_action_ref> | 242615 | ············<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_nodev_action:testaction:1</ocil:test_action_ref> |
242622 | ··········</ocil:actions> | 242616 | ··········</ocil:actions> |
242623 | ········</ocil:questionnaire> | 242617 | ········</ocil:questionnaire> |
242624 | ········<ocil:questionnaire·id="ocil:ssg- | 242618 | ········<ocil:questionnaire·id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1"> |
242625 | ··········<ocil:title> | 242619 | ··········<ocil:title>Set·SSH·Client·Alive·Interval</ocil:title> |
242626 | ··········<ocil:actions> | 242620 | ··········<ocil:actions> |
242627 | ············<ocil:test_action_ref>ocil:ssg- | 242621 | ············<ocil:test_action_ref>ocil:ssg-sshd_set_idle_timeout_action:testaction:1</ocil:test_action_ref> |
242628 | ··········</ocil:actions> | 242622 | ··········</ocil:actions> |
242629 | ········</ocil:questionnaire> | 242623 | ········</ocil:questionnaire> |
242630 | ········<ocil:questionnaire·id="ocil:ssg-ss | 242624 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_ocil:questionnaire:1"> |
242631 | ··········<ocil:title> | 242625 | ··········<ocil:title>Limit·CPU·consumption·of·the·Perf·system</ocil:title> |
242632 | ··········<ocil:actions> | 242626 | ··········<ocil:actions> |
242633 | ············<ocil:test_action_ref>ocil:ssg-ss | 242627 | ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_action:testaction:1</ocil:test_action_ref> |
242634 | ··········</ocil:actions> | 242628 | ··········</ocil:actions> |
242635 | ········</ocil:questionnaire> | 242629 | ········</ocil:questionnaire> |
242636 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1"> | ||
242637 | ········ | 242630 | ········<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1"> |
242631 | ··········<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title> | ||
242638 | ··········<ocil:actions> | 242632 | ··········<ocil:actions> |
242639 | ············<ocil:test_action_ref>ocil:ssg- | 242633 | ············<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref> |
242640 | ··········</ocil:actions> | 242634 | ··········</ocil:actions> |
242641 | ········</ocil:questionnaire> | 242635 | ········</ocil:questionnaire> |
242642 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_ocil:questionnaire:1"> | ||
242643 | ········ | 242636 | ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sudoers_ocil:questionnaire:1"> |
242637 | ··········<ocil:title>Verify·Group·Who·Owns·/etc/sudoers·File</ocil:title> | ||
242644 | ··········<ocil:actions> | 242638 | ··········<ocil:actions> |
242645 | ············<ocil:test_action_ref>ocil:ssg- | 242639 | ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sudoers_action:testaction:1</ocil:test_action_ref> |
242646 | ··········</ocil:actions> | 242640 | ··········</ocil:actions> |
242647 | ········</ocil:questionnaire> | 242641 | ········</ocil:questionnaire> |
242648 | ········<ocil:questionnaire·id="ocil:ssg- | 242642 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"> |
242649 | ··········<ocil:title>En | 242643 | ··········<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title> |
242650 | ··········<ocil:actions> | 242644 | ··········<ocil:actions> |
242651 | ············<ocil:test_action_ref>ocil:ssg- | 242645 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref> |
242652 | ··········</ocil:actions> | 242646 | ··········</ocil:actions> |
242653 | ········</ocil:questionnaire> | 242647 | ········</ocil:questionnaire> |
242654 | ········<ocil:questionnaire·id="ocil:ssg- | 242648 | ········<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1"> |
242655 | ··········<ocil:title> | 242649 | ··········<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title> |
242656 | ··········<ocil:actions> | 242650 | ··········<ocil:actions> |
242657 | ············<ocil:test_action_ref>ocil:ssg- | 242651 | ············<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref> |
242658 | ··········</ocil:actions> | 242652 | ··········</ocil:actions> |
242659 | ········</ocil:questionnaire> | 242653 | ········</ocil:questionnaire> |
242660 | ········<ocil:questionnaire·id="ocil:ssg- | 242654 | ········<ocil:questionnaire·id="ocil:ssg-installed_OS_is_vendor_supported_ocil:questionnaire:1"> |
242661 | ··········<ocil:title> | 242655 | ··········<ocil:title>The·Installed·Operating·System·Is·Vendor·Supported</ocil:title> |
242662 | ··········<ocil:actions> | 242656 | ··········<ocil:actions> |
242663 | ············<ocil:test_action_ref>ocil:ssg- | 242657 | ············<ocil:test_action_ref>ocil:ssg-installed_OS_is_vendor_supported_action:testaction:1</ocil:test_action_ref> |
242664 | ··········</ocil:actions> | 242658 | ··········</ocil:actions> |
242665 | ········</ocil:questionnaire> | 242659 | ········</ocil:questionnaire> |
242666 | ········<ocil:questionnaire·id="ocil:ssg- | 242660 | ········<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1"> |
242667 | ··········<ocil:title> | 242661 | ··········<ocil:title>Disable·IA32·emulation</ocil:title> |
242668 | ··········<ocil:actions> | 242662 | ··········<ocil:actions> |
242669 | ············<ocil:test_action_ref>ocil:ssg- | 242663 | ············<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref> |
242670 | ··········</ocil:actions> | 242664 | ··········</ocil:actions> |
242671 | ········</ocil:questionnaire> | 242665 | ········</ocil:questionnaire> |
242672 | ········<ocil:questionnaire·id="ocil:ssg- | 242666 | ········<ocil:questionnaire·id="ocil:ssg-no_files_unowned_by_user_ocil:questionnaire:1"> |
242673 | ··········<ocil:title>Ensure· | 242667 | ··········<ocil:title>Ensure·All·Files·Are·Owned·by·a·User</ocil:title> |
242674 | ··········<ocil:actions> | 242668 | ··········<ocil:actions> |
242675 | ············<ocil:test_action_ref>ocil:ssg- | 242669 | ············<ocil:test_action_ref>ocil:ssg-no_files_unowned_by_user_action:testaction:1</ocil:test_action_ref> |
242676 | ··········</ocil:actions> | 242670 | ··········</ocil:actions> |
Max diff block lines reached; 1958675/1970342 bytes (99.41%) of diff not shown. |
Offset 3, 9916 lines modified | Offset 3, 9916 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg-service_debug-shell_disabled_ocil:questionnaire:1"> | ||
11 | ······<ocil:title>Disable·debug-shell·SystemD·Service</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-service_debug-shell_disabled_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_nodev_ocil:questionnaire:1"> | 10 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_nodev_ocil:questionnaire:1"> |
17 | ······<ocil:title>Add·nodev·Option·to·/var/tmp</ocil:title> | 11 | ······<ocil:title>Add·nodev·Option·to·/var/tmp</ocil:title> |
18 | ······<ocil:actions> | 12 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_nodev_action:testaction:1</ocil:test_action_ref> | 13 | ········<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_nodev_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 14 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg- | 16 | ····<ocil:questionnaire·id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1"> |
23 | ······<ocil:title> | 17 | ······<ocil:title>Set·SSH·Client·Alive·Interval</ocil:title> |
24 | ······<ocil:actions> | 18 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-sshd_set_idle_timeout_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 20 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1"> | ||
29 | ···· | 22 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_ocil:questionnaire:1"> |
23 | ······<ocil:title>Limit·CPU·consumption·of·the·Perf·system</ocil:title> | ||
30 | ······<ocil:actions> | 24 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg-ss | 25 | ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 26 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1"> | ||
35 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1"> |
29 | ······<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title> | ||
36 | ······<ocil:actions> | 30 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg- | 31 | ········<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 32 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_ocil:questionnaire:1"> | ||
41 | ···· | 34 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sudoers_ocil:questionnaire:1"> |
35 | ······<ocil:title>Verify·Group·Who·Owns·/etc/sudoers·File</ocil:title> | ||
42 | ······<ocil:actions> | 36 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sudoers_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 38 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg- | 40 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"> |
47 | ······<ocil:title>En | 41 | ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title> |
48 | ······<ocil:actions> | 42 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 44 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-package_setroubleshoot-plugins_removed_ocil:questionnaire:1"> | ||
53 | ···· | 46 | ····<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1"> |
47 | ······<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title> | ||
54 | ······<ocil:actions> | 48 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 50 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg- | 52 | ····<ocil:questionnaire·id="ocil:ssg-installed_OS_is_vendor_supported_ocil:questionnaire:1"> |
59 | ······<ocil:title> | 53 | ······<ocil:title>The·Installed·Operating·System·Is·Vendor·Supported</ocil:title> |
60 | ······<ocil:actions> | 54 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-installed_OS_is_vendor_supported_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 56 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_min_life_existing_ocil:questionnaire:1"> | ||
65 | ···· | 58 | ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1"> |
59 | ······<ocil:title>Disable·IA32·emulation</ocil:title> | ||
66 | ······<ocil:actions> | 60 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 62 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg- | 64 | ····<ocil:questionnaire·id="ocil:ssg-no_files_unowned_by_user_ocil:questionnaire:1"> |
71 | ······<ocil:title>Ensure· | 65 | ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·User</ocil:title> |
72 | ······<ocil:actions> | 66 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg- | 67 | ········<ocil:test_action_ref>ocil:ssg-no_files_unowned_by_user_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 68 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_group_ocil:questionnaire:1"> | ||
77 | ···· | 70 | ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_sestatus_conf_ocil:questionnaire:1"> |
71 | ······<ocil:title>Verify·Group·Who·Owns·/etc/sestatus.conf·File</ocil:title> | ||
78 | ······<ocil:actions> | 72 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 74 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1"> | ||
83 | ···· | 76 | ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_noexec_ocil:questionnaire:1"> |
77 | ······<ocil:title>Add·noexec·Option·to·/boot</ocil:title> | ||
84 | ······<ocil:actions> | 78 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_noexec_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 80 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg- | 82 | ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_tally2_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 83 | ······<ocil:title>Set·Deny·For·Failed·Password·Attempts</ocil:title> |
90 | ······<ocil:actions> | 84 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_tally2_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 86 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_ | 88 | ····<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1"> |
95 | ······<ocil:title> | 89 | ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Root</ocil:title> |
96 | ······<ocil:actions> | 90 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg-file_owner_ | 91 | ········<ocil:test_action_ref>ocil:ssg-file_ownership_audit_configuration_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 92 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-ensure_pam_wheel_group_empty_ocil:questionnaire:1"> | ||
101 | ···· | 94 | ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1"> |
95 | ······<ocil:title>Ensure·rsyslog·is·Installed</ocil:title> | ||
102 | ······<ocil:actions> | 96 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 98 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg-is_fi | 100 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlinkat_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 101 | ······<ocil:title>Record·Unsuccessful·Delete·Attempts·to·Files·-·unlinkat</ocil:title> |
108 | ······<ocil:actions> | 102 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg-is_fi | 103 | ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_unlinkat_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 104 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_forwarding_ocil:questionnaire:1"> | ||
113 | ···· | 106 | ····<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_group_ownership_ocil:questionnaire:1"> |
107 | ······<ocil:title>User·Initialization·Files·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title> | ||
114 | ······<ocil:actions> | 108 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-accounts_user_dot_group_ownership_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 110 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-a | 112 | ····<ocil:questionnaire·id="ocil:ssg-package_setroubleshoot-server_removed_ocil:questionnaire:1"> |
119 | ······<ocil:title> | 113 | ······<ocil:title>Uninstall·setroubleshoot-server·Package</ocil:title> |
120 | ······<ocil:actions> | 114 | ······<ocil:actions> |
Max diff block lines reached; 1872949/1884884 bytes (99.37%) of diff not shown. |
Offset 21, 15 lines modified | Offset 21, 15 lines modified | ||
21 | ····<ds:checks> | 21 | ····<ds:checks> |
22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-oval.xml"/> | 22 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-oval.xml"/> |
23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"/> | 23 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"/> |
24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-cpe-oval.xml"/> | 24 | ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-cpe-oval.xml"/> |
25 | ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.micro.5-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.micro.5-patch.xml.bz2"/> | 25 | ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.micro.5-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.micro.5-patch.xml.bz2"/> |
26 | ····</ds:checks> | 26 | ····</ds:checks> |
27 | ··</ds:data-stream> | 27 | ··</ds:data-stream> |
28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-cpe-dictionary.xml"·timestamp="2025-0 | 28 | ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00"> |
29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> | 29 | ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd"> |
30 | ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.3"> | 30 | ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.3"> |
31 | ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.3</cpe-dict:title> | 31 | ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.3</cpe-dict:title> |
32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check> | 32 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check> |
33 | ······</cpe-dict:cpe-item> | 33 | ······</cpe-dict:cpe-item> |
34 | ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.4"> | 34 | ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.4"> |
35 | ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.4</cpe-dict:title> | 35 | ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.4</cpe-dict:title> |
Offset 41, 15 lines modified | Offset 41, 15 lines modified | ||
41 | ······</cpe-dict:cpe-item> | 41 | ······</cpe-dict:cpe-item> |
42 | ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-microos:5.2"> | 42 | ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-microos:5.2"> |
43 | ········<cpe-dict:title·xml:lang="en-us">SLE·MicroOS·5.2</cpe-dict:title> | 43 | ········<cpe-dict:title·xml:lang="en-us">SLE·MicroOS·5.2</cpe-dict:title> |
44 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check> | 44 | ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check> |
45 | ······</cpe-dict:cpe-item> | 45 | ······</cpe-dict:cpe-item> |
46 | ····</cpe-dict:cpe-list> | 46 | ····</cpe-dict:cpe-list> |
47 | ··</ds:component> | 47 | ··</ds:component> |
48 | ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-xccdf.xml"·timestamp="2025-0 | 48 | ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-xccdf.xml"·timestamp="2025-03-01T22:08:00"> |
49 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLMICRO5"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> | 49 | ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLMICRO5"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US"> |
50 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> | 50 | ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status> |
51 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·Micro·5</xccdf-1.2:title> | 51 | ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·Micro·5</xccdf-1.2:title> |
52 | ······<xccdf-1.2:description> | 52 | ······<xccdf-1.2:description> |
53 | ········This·guide·presents·a·catalog·of·security-relevant | 53 | ········This·guide·presents·a·catalog·of·security-relevant |
54 | configuration·settings·for·SUSE·Linux·Enterprise·Micro·5.·It·is·a·rendering·of | 54 | configuration·settings·for·SUSE·Linux·Enterprise·Micro·5.·It·is·a·rendering·of |
55 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) | 55 | content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF) |
Offset 124816, 15 lines modified | Offset 124816, 15 lines modified | ||
124816 | ··············<xccdf-1.2:check-content-ref·href="ssg-slmicro5-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_percentage_ocil:questionnaire:1"/> | 124816 | ··············<xccdf-1.2:check-content-ref·href="ssg-slmicro5-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_percentage_ocil:questionnaire:1"/> |
124817 | ············</xccdf-1.2:check> | 124817 | ············</xccdf-1.2:check> |
124818 | ··········</xccdf-1.2:Rule> | 124818 | ··········</xccdf-1.2:Rule> |
124819 | ········</xccdf-1.2:Group> | 124819 | ········</xccdf-1.2:Group> |
124820 | ······</xccdf-1.2:Group> | 124820 | ······</xccdf-1.2:Group> |
124821 | ····</xccdf-1.2:Benchmark> | 124821 | ····</xccdf-1.2:Benchmark> |
124822 | ··</ds:component> | 124822 | ··</ds:component> |
124823 | ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-oval.xml"·timestamp="2025-0 | 124823 | ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-oval.xml"·timestamp="2025-03-01T22:08:00"> |
124824 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> | 124824 | ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd"> |
124825 | ······<oval-def:generator> | 124825 | ······<oval-def:generator> |
124826 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> | 124826 | ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name> |
124827 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> | 124827 | ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.4</oval:product_version> |
124828 | ········<oval:schema_version>5.11</oval:schema_version> | 124828 | ········<oval:schema_version>5.11</oval:schema_version> |
124829 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> | 124829 | ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp> |
124830 | ······</oval-def:generator> | 124830 | ······</oval-def:generator> |
Offset 146446, 5421 lines modified | Offset 146446, 5421 lines modified | ||
146446 | ············</oval-def:arithmetic> | 146446 | ············</oval-def:arithmetic> |
146447 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> | 146447 | ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/> |
146448 | ··········</oval-def:arithmetic> | 146448 | ··········</oval-def:arithmetic> |
146449 | ········</oval-def:local_variable> | 146449 | ········</oval-def:local_variable> |
146450 | ······</oval-def:variables> | 146450 | ······</oval-def:variables> |
146451 | ····</oval-def:oval_definitions> | 146451 | ····</oval-def:oval_definitions> |
146452 | ··</ds:component> | 146452 | ··</ds:component> |
146453 | ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"·timestamp="2025-0 | 146453 | ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"·timestamp="2025-03-01T22:08:00"> |
146454 | ····<ocil:ocil> | 146454 | ····<ocil:ocil> |
146455 | ······<ocil:generator> | 146455 | ······<ocil:generator> |
146456 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 146456 | ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
146457 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 146457 | ········<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
146458 | ········<ocil:schema_version>2.0</ocil:schema_version> | 146458 | ········<ocil:schema_version>2.0</ocil:schema_version> |
146459 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 146459 | ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
146460 | ······</ocil:generator> | 146460 | ······</ocil:generator> |
146461 | ······<ocil:questionnaires> | 146461 | ······<ocil:questionnaires> |
146462 | ········<ocil:questionnaire·id="ocil:ssg- | 146462 | ········<ocil:questionnaire·id="ocil:ssg-service_xinetd_disabled_ocil:questionnaire:1"> |
146463 | ··········<ocil:title>Disable·xinetd·Service</ocil:title> | ||
146463 | ··········<ocil:title>Configure·Time·Service·Maxpoll·Interval</ocil:title> | ||
146464 | ··········<ocil:actions> | ||
146465 | ············<ocil:test_action_ref>ocil:ssg-chronyd_or_ntpd_set_maxpoll_action:testaction:1</ocil:test_action_ref> | ||
146466 | ··········</ocil:actions> | ||
146467 | ········</ocil:questionnaire> | ||
146468 | ········<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1"> | ||
146469 | ··········<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title> | ||
146470 | ··········<ocil:actions> | 146464 | ··········<ocil:actions> |
146471 | ············<ocil:test_action_ref>ocil:ssg- | 146465 | ············<ocil:test_action_ref>ocil:ssg-service_xinetd_disabled_action:testaction:1</ocil:test_action_ref> |
146472 | ··········</ocil:actions> | 146466 | ··········</ocil:actions> |
146473 | ········</ocil:questionnaire> | 146467 | ········</ocil:questionnaire> |
146474 | ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1"> | ||
146475 | ········ | 146468 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1"> |
146469 | ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title> | ||
146476 | ··········<ocil:actions> | 146470 | ··········<ocil:actions> |
146477 | ············<ocil:test_action_ref>ocil:ssg- | 146471 | ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref> |
146478 | ··········</ocil:actions> | 146472 | ··········</ocil:actions> |
146479 | ········</ocil:questionnaire> | 146473 | ········</ocil:questionnaire> |
146480 | ········<ocil:questionnaire·id="ocil:ssg- | 146474 | ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1"> |
146481 | ··········<ocil:title> | 146475 | ··········<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title> |
146482 | ··········<ocil:actions> | 146476 | ··········<ocil:actions> |
146483 | ············<ocil:test_action_ref>ocil:ssg- | 146477 | ············<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref> |
146484 | ··········</ocil:actions> | 146478 | ··········</ocil:actions> |
146485 | ········</ocil:questionnaire> | 146479 | ········</ocil:questionnaire> |
146486 | ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1"> | ||
146487 | ········ | 146480 | ········<ocil:questionnaire·id="ocil:ssg-service_nftables_enabled_ocil:questionnaire:1"> |
146481 | ··········<ocil:title>Verify·nftables·Service·is·Enabled</ocil:title> | ||
146488 | ··········<ocil:actions> | 146482 | ··········<ocil:actions> |
146489 | ············<ocil:test_action_ref>ocil:ssg-s | 146483 | ············<ocil:test_action_ref>ocil:ssg-service_nftables_enabled_action:testaction:1</ocil:test_action_ref> |
146490 | ··········</ocil:actions> | 146484 | ··········</ocil:actions> |
146491 | ········</ocil:questionnaire> | 146485 | ········</ocil:questionnaire> |
146492 | ········<ocil:questionnaire·id="ocil:ssg- | 146486 | ········<ocil:questionnaire·id="ocil:ssg-journald_storage_ocil:questionnaire:1"> |
146493 | ··········<ocil:title>En | 146487 | ··········<ocil:title>Ensure·journald·is·configured·to·write·log·files·to·persistent·disk</ocil:title> |
146494 | ··········<ocil:actions> | 146488 | ··········<ocil:actions> |
146495 | ············<ocil:test_action_ref>ocil:ssg- | 146489 | ············<ocil:test_action_ref>ocil:ssg-journald_storage_action:testaction:1</ocil:test_action_ref> |
146496 | ··········</ocil:actions> | 146490 | ··········</ocil:actions> |
146497 | ········</ocil:questionnaire> | 146491 | ········</ocil:questionnaire> |
146498 | ········<ocil:questionnaire·id="ocil:ssg- | 146492 | ········<ocil:questionnaire·id="ocil:ssg-package_squid_removed_ocil:questionnaire:1"> |
146499 | ··········<ocil:title> | 146493 | ··········<ocil:title>Uninstall·squid·Package</ocil:title> |
146500 | ··········<ocil:actions> | 146494 | ··········<ocil:actions> |
146501 | ············<ocil:test_action_ref>ocil:ssg- | 146495 | ············<ocil:test_action_ref>ocil:ssg-package_squid_removed_action:testaction:1</ocil:test_action_ref> |
146502 | ··········</ocil:actions> | 146496 | ··········</ocil:actions> |
146503 | ········</ocil:questionnaire> | 146497 | ········</ocil:questionnaire> |
146504 | ········<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_ciphers_ordered_stig_ocil:questionnaire:1"> | ||
146505 | ········ | 146498 | ········<ocil:questionnaire·id="ocil:ssg-auditd_audispd_network_failure_action_ocil:questionnaire:1"> |
146499 | ··········<ocil:title>Configure·audispd's·Plugin·network_failure_action·On·Network·Failure</ocil:title> | ||
146506 | ··········<ocil:actions> | 146500 | ··········<ocil:actions> |
146507 | ············<ocil:test_action_ref>ocil:ssg- | 146501 | ············<ocil:test_action_ref>ocil:ssg-auditd_audispd_network_failure_action_action:testaction:1</ocil:test_action_ref> |
146508 | ··········</ocil:actions> | 146502 | ··········</ocil:actions> |
146509 | ········</ocil:questionnaire> | 146503 | ········</ocil:questionnaire> |
146510 | ········<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1"> | ||
146511 | ········ | 146504 | ········<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1"> |
146505 | ··········<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title> | ||
146512 | ··········<ocil:actions> | 146506 | ··········<ocil:actions> |
146513 | ············<ocil:test_action_ref>ocil:ssg- | 146507 | ············<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref> |
146514 | ··········</ocil:actions> | 146508 | ··········</ocil:actions> |
146515 | ········</ocil:questionnaire> | 146509 | ········</ocil:questionnaire> |
146516 | ········<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1"> | ||
146517 | ········ | 146510 | ········<ocil:questionnaire·id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1"> |
146511 | ··········<ocil:title>Ensure·All·Files·Are·Owned·by·a·Group</ocil:title> | ||
146518 | ··········<ocil:actions> | 146512 | ··········<ocil:actions> |
Max diff block lines reached; 1047462/1059077 bytes (98.90%) of diff not shown. |
Offset 3, 5412 lines modified | Offset 3, 5412 lines modified | ||
3 | ··<ocil:generator> | 3 | ··<ocil:generator> |
4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> | 4 | ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name> |
5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> | 5 | ····<ocil:product_version>ssg:·0.1.76</ocil:product_version> |
6 | ····<ocil:schema_version>2.0</ocil:schema_version> | 6 | ····<ocil:schema_version>2.0</ocil:schema_version> |
7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> | 7 | ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp> |
8 | ··</ocil:generator> | 8 | ··</ocil:generator> |
9 | ··<ocil:questionnaires> | 9 | ··<ocil:questionnaires> |
10 | ····<ocil:questionnaire·id="ocil:ssg- | 10 | ····<ocil:questionnaire·id="ocil:ssg-service_xinetd_disabled_ocil:questionnaire:1"> |
11 | ······<ocil:title>Disable·xinetd·Service</ocil:title> | ||
11 | ······<ocil:title>Configure·Time·Service·Maxpoll·Interval</ocil:title> | ||
12 | ······<ocil:actions> | ||
13 | ········<ocil:test_action_ref>ocil:ssg-chronyd_or_ntpd_set_maxpoll_action:testaction:1</ocil:test_action_ref> | ||
14 | ······</ocil:actions> | ||
15 | ····</ocil:questionnaire> | ||
16 | ····<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1"> | ||
17 | ······<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title> | ||
18 | ······<ocil:actions> | 12 | ······<ocil:actions> |
19 | ········<ocil:test_action_ref>ocil:ssg- | 13 | ········<ocil:test_action_ref>ocil:ssg-service_xinetd_disabled_action:testaction:1</ocil:test_action_ref> |
20 | ······</ocil:actions> | 14 | ······</ocil:actions> |
21 | ····</ocil:questionnaire> | 15 | ····</ocil:questionnaire> |
22 | ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1"> | ||
23 | ···· | 16 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1"> |
17 | ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title> | ||
24 | ······<ocil:actions> | 18 | ······<ocil:actions> |
25 | ········<ocil:test_action_ref>ocil:ssg- | 19 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref> |
26 | ······</ocil:actions> | 20 | ······</ocil:actions> |
27 | ····</ocil:questionnaire> | 21 | ····</ocil:questionnaire> |
28 | ····<ocil:questionnaire·id="ocil:ssg- | 22 | ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1"> |
29 | ······<ocil:title> | 23 | ······<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title> |
30 | ······<ocil:actions> | 24 | ······<ocil:actions> |
31 | ········<ocil:test_action_ref>ocil:ssg- | 25 | ········<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref> |
32 | ······</ocil:actions> | 26 | ······</ocil:actions> |
33 | ····</ocil:questionnaire> | 27 | ····</ocil:questionnaire> |
34 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1"> | ||
35 | ···· | 28 | ····<ocil:questionnaire·id="ocil:ssg-service_nftables_enabled_ocil:questionnaire:1"> |
29 | ······<ocil:title>Verify·nftables·Service·is·Enabled</ocil:title> | ||
36 | ······<ocil:actions> | 30 | ······<ocil:actions> |
37 | ········<ocil:test_action_ref>ocil:ssg-s | 31 | ········<ocil:test_action_ref>ocil:ssg-service_nftables_enabled_action:testaction:1</ocil:test_action_ref> |
38 | ······</ocil:actions> | 32 | ······</ocil:actions> |
39 | ····</ocil:questionnaire> | 33 | ····</ocil:questionnaire> |
40 | ····<ocil:questionnaire·id="ocil:ssg- | 34 | ····<ocil:questionnaire·id="ocil:ssg-journald_storage_ocil:questionnaire:1"> |
41 | ······<ocil:title>En | 35 | ······<ocil:title>Ensure·journald·is·configured·to·write·log·files·to·persistent·disk</ocil:title> |
42 | ······<ocil:actions> | 36 | ······<ocil:actions> |
43 | ········<ocil:test_action_ref>ocil:ssg- | 37 | ········<ocil:test_action_ref>ocil:ssg-journald_storage_action:testaction:1</ocil:test_action_ref> |
44 | ······</ocil:actions> | 38 | ······</ocil:actions> |
45 | ····</ocil:questionnaire> | 39 | ····</ocil:questionnaire> |
46 | ····<ocil:questionnaire·id="ocil:ssg- | 40 | ····<ocil:questionnaire·id="ocil:ssg-package_squid_removed_ocil:questionnaire:1"> |
47 | ······<ocil:title> | 41 | ······<ocil:title>Uninstall·squid·Package</ocil:title> |
48 | ······<ocil:actions> | 42 | ······<ocil:actions> |
49 | ········<ocil:test_action_ref>ocil:ssg- | 43 | ········<ocil:test_action_ref>ocil:ssg-package_squid_removed_action:testaction:1</ocil:test_action_ref> |
50 | ······</ocil:actions> | 44 | ······</ocil:actions> |
51 | ····</ocil:questionnaire> | 45 | ····</ocil:questionnaire> |
52 | ····<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_ciphers_ordered_stig_ocil:questionnaire:1"> | ||
53 | ···· | 46 | ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_network_failure_action_ocil:questionnaire:1"> |
47 | ······<ocil:title>Configure·audispd's·Plugin·network_failure_action·On·Network·Failure</ocil:title> | ||
54 | ······<ocil:actions> | 48 | ······<ocil:actions> |
55 | ········<ocil:test_action_ref>ocil:ssg- | 49 | ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_network_failure_action_action:testaction:1</ocil:test_action_ref> |
56 | ······</ocil:actions> | 50 | ······</ocil:actions> |
57 | ····</ocil:questionnaire> | 51 | ····</ocil:questionnaire> |
58 | ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1"> | ||
59 | ···· | 52 | ····<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1"> |
53 | ······<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title> | ||
60 | ······<ocil:actions> | 54 | ······<ocil:actions> |
61 | ········<ocil:test_action_ref>ocil:ssg- | 55 | ········<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref> |
62 | ······</ocil:actions> | 56 | ······</ocil:actions> |
63 | ····</ocil:questionnaire> | 57 | ····</ocil:questionnaire> |
64 | ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1"> | ||
65 | ···· | 58 | ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1"> |
59 | ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·Group</ocil:title> | ||
66 | ······<ocil:actions> | 60 | ······<ocil:actions> |
67 | ········<ocil:test_action_ref>ocil:ssg- | 61 | ········<ocil:test_action_ref>ocil:ssg-file_permissions_ungroupowned_action:testaction:1</ocil:test_action_ref> |
68 | ······</ocil:actions> | 62 | ······</ocil:actions> |
69 | ····</ocil:questionnaire> | 63 | ····</ocil:questionnaire> |
70 | ····<ocil:questionnaire·id="ocil:ssg-a | 64 | ····<ocil:questionnaire·id="ocil:ssg-package_talk_removed_ocil:questionnaire:1"> |
71 | ······<ocil:title> | 65 | ······<ocil:title>Uninstall·talk·Package</ocil:title> |
72 | ······<ocil:actions> | 66 | ······<ocil:actions> |
73 | ········<ocil:test_action_ref>ocil:ssg-a | 67 | ········<ocil:test_action_ref>ocil:ssg-package_talk_removed_action:testaction:1</ocil:test_action_ref> |
74 | ······</ocil:actions> | 68 | ······</ocil:actions> |
75 | ····</ocil:questionnaire> | 69 | ····</ocil:questionnaire> |
76 | ····<ocil:questionnaire·id="ocil:ssg- | 70 | ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1"> |
77 | ······<ocil:title> | 71 | ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title> |
78 | ······<ocil:actions> | 72 | ······<ocil:actions> |
79 | ········<ocil:test_action_ref>ocil:ssg- | 73 | ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref> |
80 | ······</ocil:actions> | 74 | ······</ocil:actions> |
81 | ····</ocil:questionnaire> | 75 | ····</ocil:questionnaire> |
82 | ····<ocil:questionnaire·id="ocil:ssg- | 76 | ····<ocil:questionnaire·id="ocil:ssg-cracklib_accounts_password_pam_minlen_ocil:questionnaire:1"> |
83 | ······<ocil:title> | 77 | ······<ocil:title>Set·Password·Minimum·Length</ocil:title> |
84 | ······<ocil:actions> | 78 | ······<ocil:actions> |
85 | ········<ocil:test_action_ref>ocil:ssg- | 79 | ········<ocil:test_action_ref>ocil:ssg-cracklib_accounts_password_pam_minlen_action:testaction:1</ocil:test_action_ref> |
86 | ······</ocil:actions> | 80 | ······</ocil:actions> |
87 | ····</ocil:questionnaire> | 81 | ····</ocil:questionnaire> |
88 | ····<ocil:questionnaire·id="ocil:ssg- | 82 | ····<ocil:questionnaire·id="ocil:ssg-dir_system_commands_root_owned_ocil:questionnaire:1"> |
89 | ······<ocil:title> | 83 | ······<ocil:title>Verify·that·system·commands·directories·have·root·ownership</ocil:title> |
90 | ······<ocil:actions> | 84 | ······<ocil:actions> |
91 | ········<ocil:test_action_ref>ocil:ssg- | 85 | ········<ocil:test_action_ref>ocil:ssg-dir_system_commands_root_owned_action:testaction:1</ocil:test_action_ref> |
92 | ······</ocil:actions> | 86 | ······</ocil:actions> |
93 | ····</ocil:questionnaire> | 87 | ····</ocil:questionnaire> |
94 | ····<ocil:questionnaire·id="ocil:ssg-package_vsftpd_removed_ocil:questionnaire:1"> | ||
95 | ····· | 88 | ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1"> |
89 | ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title> | ||
96 | ······<ocil:actions> | 90 | ······<ocil:actions> |
97 | ········<ocil:test_action_ref>ocil:ssg- | 91 | ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref> |
98 | ······</ocil:actions> | 92 | ······</ocil:actions> |
99 | ····</ocil:questionnaire> | 93 | ····</ocil:questionnaire> |
100 | ····<ocil:questionnaire·id="ocil:ssg-cracklib_accounts_password_pam_lcredit_ocil:questionnaire:1"> | ||
101 | ···· | 94 | ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1"> |
95 | ······<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title> | ||
102 | ······<ocil:actions> | 96 | ······<ocil:actions> |
103 | ········<ocil:test_action_ref>ocil:ssg- | 97 | ········<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref> |
104 | ······</ocil:actions> | 98 | ······</ocil:actions> |
105 | ····</ocil:questionnaire> | 99 | ····</ocil:questionnaire> |
106 | ····<ocil:questionnaire·id="ocil:ssg- | 100 | ····<ocil:questionnaire·id="ocil:ssg-display_login_attempts_ocil:questionnaire:1"> |
107 | ······<ocil:title> | 101 | ······<ocil:title>Ensure·PAM·Displays·Last·Logon/Access·Notification</ocil:title> |
108 | ······<ocil:actions> | 102 | ······<ocil:actions> |
109 | ········<ocil:test_action_ref>ocil:ssg- | 103 | ········<ocil:test_action_ref>ocil:ssg-display_login_attempts_action:testaction:1</ocil:test_action_ref> |
110 | ······</ocil:actions> | 104 | ······</ocil:actions> |
111 | ····</ocil:questionnaire> | 105 | ····</ocil:questionnaire> |
112 | ····<ocil:questionnaire·id="ocil:ssg- | 106 | ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1"> |
113 | ······<ocil:title> | 107 | ······<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title> |
114 | ······<ocil:actions> | 108 | ······<ocil:actions> |
115 | ········<ocil:test_action_ref>ocil:ssg- | 109 | ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref> |
116 | ······</ocil:actions> | 110 | ······</ocil:actions> |
117 | ····</ocil:questionnaire> | 111 | ····</ocil:questionnaire> |
118 | ····<ocil:questionnaire·id="ocil:ssg-accounts_authorized_local_users_ocil:questionnaire:1"> | ||
119 | ···· | 112 | ····<ocil:questionnaire·id="ocil:ssg-sudoers_default_includedir_ocil:questionnaire:1"> |
113 | ······<ocil:title>Ensure·sudo·only·includes·the·default·configuration·directory</ocil:title> | ||
120 | ······<ocil:actions> | 114 | ······<ocil:actions> |
Max diff block lines reached; 999168/1011373 bytes (98.79%) of diff not shown. |